Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-03-15 CVE-2018-18255 Improper Authentication vulnerability in Capmon Access Manager 5.4.1.1005
An issue was discovered in CapMon Access Manager 5.4.1.1005.
local
low complexity
capmon CWE-287
7.8
2019-03-14 CVE-2018-12192 Improper Authentication vulnerability in Intel products
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.
low complexity
intel CWE-287
6.8
2019-03-07 CVE-2019-3775 Improper Authentication vulnerability in Cloudfoundry UAA Release
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address.
network
low complexity
cloudfoundry CWE-287
6.5
2019-02-28 CVE-2018-12399 Improper Authentication vulnerability in multiple products
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol.
network
low complexity
mozilla canonical CWE-287
4.3
2019-02-26 CVE-2019-7392 Improper Authentication vulnerability in Broadcom Privileged Access Manager
An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.
network
low complexity
broadcom CWE-287
critical
9.1
2019-02-25 CVE-2019-9124 Improper Authentication vulnerability in D-Link Dir-878 Firmware 1.12B01
An issue was discovered on D-Link DIR-878 1.12B01 devices.
network
low complexity
d-link CWE-287
critical
9.8
2019-02-21 CVE-2019-1666 Improper Authentication vulnerability in Cisco Hyperflex HX Data Platform
A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service.
network
low complexity
cisco CWE-287
5.3
2019-02-21 CVE-2019-1664 Improper Authentication vulnerability in Cisco Hyperflex HX Data Platform
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster.
local
low complexity
cisco CWE-287
7.8
2019-02-21 CVE-2019-1662 Improper Authentication vulnerability in Cisco Prime Collaboration Assurance
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user.
network
low complexity
cisco CWE-287
critical
9.1
2019-02-13 CVE-2019-5909 Improper Authentication vulnerability in Yokogawa products
License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspecified vectors.
network
low complexity
yokogawa CWE-287
critical
9.8