Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-05-10 CVE-2018-7941 Improper Authentication vulnerability in Huawei products
Huawei iBMC V200R002C60 have an authentication bypass vulnerability.
network
low complexity
huawei CWE-287
8.8
2018-05-10 CVE-2018-7940 Improper Authentication vulnerability in Huawei Mate 9 Firmware and Mate 9 PRO Firmware
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability.
low complexity
huawei CWE-287
6.2
2018-05-09 CVE-2018-6020 Improper Authentication vulnerability in Silextechnology products
In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.
network
low complexity
silextechnology CWE-287
6.5
2018-05-09 CVE-2018-10683 Improper Authentication vulnerability in Redhat Wildfly 10.1.2
An issue was discovered in WildFly 10.1.2.Final.
network
low complexity
redhat CWE-287
critical
9.8
2018-05-09 CVE-2018-10682 Improper Authentication vulnerability in Wildfly 10.1.2
An issue was discovered in WildFly 10.1.2.Final.
network
low complexity
wildfly CWE-287
critical
9.8
2018-05-04 CVE-2017-3775 Improper Authentication vulnerability in Lenovo products
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it.
high complexity
lenovo CWE-287
6.4
2018-05-04 CVE-2018-10641 Improper Authentication vulnerability in Dlink Dir-601 Firmware 1.02Na
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
network
high complexity
dlink CWE-287
8.1
2018-05-04 CVE-2018-10561 Improper Authentication vulnerability in Dasannetworks Gpon Router Firmware
An issue was discovered on Dasan GPON home routers.
network
low complexity
dasannetworks CWE-287
critical
9.8
2018-05-02 CVE-2018-0247 Improper Authentication vulnerability in Cisco products
A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic.
low complexity
cisco CWE-287
4.7
2018-05-02 CVE-2018-10544 Improper Authentication vulnerability in Meross Mss110 Firmware 1.1.24
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.
network
low complexity
meross CWE-287
critical
9.8