Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-02-21 CVE-2019-1664 Improper Authentication vulnerability in Cisco Hyperflex HX Data Platform
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster.
local
low complexity
cisco CWE-287
7.8
2019-02-21 CVE-2019-1662 Improper Authentication vulnerability in Cisco Prime Collaboration Assurance
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user.
network
low complexity
cisco CWE-287
critical
9.1
2019-02-13 CVE-2019-5909 Improper Authentication vulnerability in Yokogawa products
License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspecified vectors.
network
low complexity
yokogawa CWE-287
critical
9.8
2019-02-12 CVE-2018-19645 Improper Authentication vulnerability in Microfocus Solutions Business Manager
An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
network
low complexity
microfocus CWE-287
critical
9.8
2019-02-12 CVE-2019-6527 Improper Authentication vulnerability in Kunbus Pr100088 Modbus Gateway Firmware 1.0.10232/1.1.13166
PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.
network
low complexity
kunbus CWE-287
critical
9.8
2019-02-06 CVE-2019-3825 Improper Authentication vulnerability in multiple products
A vulnerability was discovered in gdm before 3.31.4.
high complexity
gnome canonical redhat CWE-287
6.4
2019-02-06 CVE-2019-3820 Improper Authentication vulnerability in multiple products
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions.
low complexity
gnome opensuse canonical CWE-287
4.3
2019-02-05 CVE-2019-6521 Improper Authentication vulnerability in Advantech Webaccess/Scada 8.3
WebAccess/SCADA, Version 8.3.
network
low complexity
advantech CWE-287
8.6
2019-02-05 CVE-2019-6519 Improper Authentication vulnerability in Advantech Webaccess/Scada 8.3
WebAccess/SCADA, Version 8.3.
network
low complexity
advantech CWE-287
critical
9.8
2019-02-05 CVE-2018-18505 Improper Authentication vulnerability in multiple products
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation.
network
low complexity
mozilla canonical debian redhat CWE-287
critical
10.0