Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-06-28 CVE-2018-14868 Improper Authentication vulnerability in Odoo 9.0
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
network
low complexity
odoo CWE-287
6.5
2019-06-27 CVE-2018-15556 Improper Authentication vulnerability in Actiontec Web6000Q Firmware 1.1.02.22
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.
network
low complexity
actiontec CWE-287
critical
9.8
2019-06-27 CVE-2019-7226 Improper Authentication vulnerability in ABB Pb610 Panel Builder 600 Firmware 1.91/2.8.0.367
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions.
low complexity
abb CWE-287
8.8
2019-06-24 CVE-2019-10689 Improper Authentication vulnerability in Polycom products
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
low complexity
polycom CWE-287
6.5
2019-06-19 CVE-2019-2018 Improper Authentication vulnerability in Google Android 8.1/9.0
In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause.
network
low complexity
google CWE-287
8.8
2019-06-19 CVE-2019-11232 Improper Authentication vulnerability in EIC Biyan 1.57/2.8
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.
network
low complexity
eic CWE-287
critical
9.8
2019-06-18 CVE-2018-18877 Improper Authentication vulnerability in Columbiaweather Weather Microserver Firmware Ms2.6.9900
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.
network
low complexity
columbiaweather CWE-287
8.8
2019-06-18 CVE-2019-10998 Improper Authentication vulnerability in Phoenixcontact products
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices.
low complexity
phoenixcontact CWE-287
6.8
2019-06-17 CVE-2017-9389 Improper Authentication vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-287
8.8
2019-06-17 CVE-2017-9383 Improper Authentication vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-287
critical
9.9