Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-06-20 CVE-2018-12446 Improper Authentication vulnerability in Dropbox 98.2.2
An issue was discovered in the com.dropbox.android application 98.2.2 for Android.
local
high complexity
dropbox CWE-287
3.6
2018-06-20 CVE-2018-12445 Improper Authentication vulnerability in Dropbox 98.2.2
An issue was discovered in the com.dropbox.android application 98.2.2 for Android.
high complexity
dropbox CWE-287
3.1
2018-06-18 CVE-2018-9024 Improper Authentication vulnerability in Broadcom Privileged Access Manager
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.
network
low complexity
broadcom CWE-287
5.3
2018-06-15 CVE-2018-1085 Improper Authentication vulnerability in Redhat Openshift Container Platform
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled.
network
low complexity
redhat CWE-287
critical
9.8
2018-06-13 CVE-2018-12271 Improper Authentication vulnerability in Dropbox 100.2
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS.
high complexity
dropbox CWE-287
6.4
2018-06-13 CVE-2018-11407 Improper Authentication vulnerability in Sensiolabs Symfony
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7.
network
low complexity
sensiolabs CWE-287
critical
9.8
2018-06-08 CVE-2018-12049 Improper Authentication vulnerability in Canon Lbp6030W Firmware
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device.
network
low complexity
canon CWE-287
critical
9.8
2018-06-08 CVE-2018-12048 Improper Authentication vulnerability in Canon Lbp7110Cw Firmware
A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device.
network
low complexity
canon CWE-287
critical
9.8
2018-06-07 CVE-2018-0321 Improper Authentication vulnerability in Cisco products
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system.
network
low complexity
cisco CWE-287
critical
9.8
2018-06-07 CVE-2018-0319 Improper Authentication vulnerability in Cisco products
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device.
network
low complexity
cisco CWE-287
critical
9.8