Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-08-16 CVE-2018-13434 Improper Authentication vulnerability in Linecorp Line 8.8.0
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS.
high complexity
linecorp CWE-287
6.3
2018-08-15 CVE-2018-15152 Improper Authentication vulnerability in Open-Emr Openemr
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.
network
low complexity
open-emr CWE-287
critical
9.1
2018-08-14 CVE-2018-2449 Improper Authentication vulnerability in SAP Supplier Relationship Management MDM Catalog 3.73/7.31/7.32
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user.
network
low complexity
sap CWE-287
8.6
2018-08-13 CVE-2018-14781 Improper Authentication vulnerability in Medtronicdiabetes products
Medtronic MMT 508 MiniMed insulin pump, 522 / MMT - 722 Paradigm REAL-TIME, 523 / MMT - 723 Paradigm Revel, 523K / MMT - 723K Paradigm Revel, and 551 / MMT - 751 MiniMed 530G The models identified above, when paired with a remote controller and having the "easy bolus" and "remote bolus" options enabled (non-default), are vulnerable to a capture-replay attack.
high complexity
medtronicdiabetes CWE-287
5.3
2018-08-13 CVE-2018-11770 Improper Authentication vulnerability in Apache Spark
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit.
network
high complexity
apache CWE-287
4.2
2018-08-12 CVE-2018-3775 Improper Authentication vulnerability in Nextcloud Server
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
network
low complexity
nextcloud CWE-287
8.8
2018-08-10 CVE-2018-14782 Improper Authentication vulnerability in Netcommwireless Nwl-25 Firmware 2.0.29.11
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.
network
low complexity
netcommwireless CWE-287
7.5
2018-08-10 CVE-2018-10630 Improper Authentication vulnerability in Crestron MC3 Firmware and Tsw-X60 Firmware
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it.
network
low complexity
crestron CWE-287
critical
9.8
2018-08-06 CVE-2018-7069 Improper Authentication vulnerability in HP Centralview Fraud Risk Management
HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1.
network
low complexity
hp CWE-287
7.5
2018-08-06 CVE-2018-7058 Improper Authentication vulnerability in HP Aruba Clearpass Policy Manager
Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system.
network
low complexity
hp CWE-287
critical
9.8