Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-11-26 CVE-2019-6675 Improper Authentication vulnerability in F5 products
BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass.
network
low complexity
f5 CWE-287
critical
9.8
2019-11-26 CVE-2019-14856 Improper Authentication vulnerability in multiple products
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
network
low complexity
redhat opensuse CWE-287
6.5
2019-11-26 CVE-2019-15987 Improper Authentication vulnerability in Cisco products
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames.
network
low complexity
cisco CWE-287
5.3
2019-11-26 CVE-2019-18250 Improper Authentication vulnerability in ABB products
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.
network
low complexity
abb CWE-287
critical
9.8
2019-11-25 CVE-2019-18374 Improper Authentication vulnerability in Broadcom Symantec Critical System Protection 8.0.0
Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.
network
low complexity
broadcom CWE-287
critical
9.8
2019-11-22 CVE-2019-16286 Improper Authentication vulnerability in HP Thinpro Linux
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands.
low complexity
hp CWE-287
6.8
2019-11-22 CVE-2019-3654 Improper Authentication vulnerability in Mcafee Client Proxy
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which should only be generated by the network administrator.
local
low complexity
mcafee CWE-287
8.6
2019-11-21 CVE-2014-2904 Improper Authentication vulnerability in Wolfssl
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
network
low complexity
wolfssl CWE-287
7.5
2019-11-21 CVE-2019-19006 Improper Authentication vulnerability in Sangoma Freepbx
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
network
low complexity
sangoma CWE-287
critical
9.8
2019-11-14 CVE-2019-15803 Improper Authentication vulnerability in Zyxel products
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0.
network
low complexity
zyxel CWE-287
critical
9.1