Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-10-19 CVE-2018-12667 Improper Authentication vulnerability in Sv3C H.264 POE IP Camera Firmware V2.3.4.2103S50Ntdb20170508B/V2.3.4.2103S50Ntdb20170823B
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerability that allows requests to be made to back-end CGI scripts without a valid session.
network
low complexity
sv3c CWE-287
critical
9.8
2018-10-19 CVE-2018-12666 Improper Authentication vulnerability in Sv3C H.264 POE IP Camera Firmware V2.3.4.2103S50Ntdb20170508B/V2.3.4.2103S50Ntdb20170823B
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255.
network
low complexity
sv3c CWE-287
critical
9.8
2018-10-18 CVE-2018-1822 Improper Authentication vulnerability in IBM Flashsystem 840 Firmware and Flashsystem 900 Firmware
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password.
network
low complexity
ibm CWE-287
critical
9.8
2018-10-17 CVE-2018-7989 Improper Authentication vulnerability in Huawei Mate 10 PRO Firmware
Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnerability.
low complexity
huawei CWE-287
4.6
2018-10-17 CVE-2018-7076 Improper Authentication vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04.
network
low complexity
hp CWE-287
critical
9.8
2018-10-17 CVE-2018-10933 Improper Authentication vulnerability in multiple products
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.
network
low complexity
libssh canonical debian redhat netapp oracle CWE-287
critical
9.1
2018-10-16 CVE-2018-18389 Improper Authentication vulnerability in Neo4J
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.
network
low complexity
neo4j CWE-287
critical
9.8
2018-10-15 CVE-2018-17534 Improper Authentication vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control.
low complexity
teltonika CWE-287
6.8
2018-10-11 CVE-2018-1738 Improper Authentication vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms.
network
low complexity
ibm CWE-287
7.1
2018-10-10 CVE-2018-18061 Improper Authentication vulnerability in Tecrail Responsive Filemanager 9.8.1
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1.
network
low complexity
tecrail CWE-287
7.5