Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-15371 Improper Authentication vulnerability in Cisco IOS XE 16.3(1)
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device.
local
low complexity
cisco CWE-287
6.7
2018-10-05 CVE-2018-0435 Improper Authentication vulnerability in Cisco Umbrella
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations.
network
low complexity
cisco CWE-287
critical
9.1
2018-10-05 CVE-2013-7465 Improper Authentication vulnerability in Icecoldapps Servers Ultimate 6.0.2
Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary code by uploading PHP scripts.
network
low complexity
icecoldapps CWE-287
critical
9.8
2018-10-04 CVE-2018-0505 Improper Authentication vulnerability in multiple products
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
network
low complexity
mediawiki debian CWE-287
6.5
2018-10-04 CVE-2018-12472 Improper Authentication vulnerability in Suse Subscription Management Tool
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server.
network
low complexity
suse CWE-287
critical
9.1
2018-10-03 CVE-2018-6689 Improper Authentication vulnerability in Mcafee Data Loss Prevention Endpoint
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.
local
low complexity
mcafee CWE-287
7.8
2018-10-02 CVE-2018-17786 Improper Authentication vulnerability in D-Link Dir-823G Firmware
On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code.
network
low complexity
d-link CWE-287
critical
9.8
2018-10-01 CVE-2018-1672 Improper Authentication vulnerability in IBM Websphere Portal
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user.
network
low complexity
ibm CWE-287
6.3
2018-09-28 CVE-2018-9080 Improper Authentication vulnerability in Lenovo products
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value.
network
high complexity
lenovo CWE-287
5.9
2018-09-27 CVE-2018-7108 Improper Authentication vulnerability in HPE Storageworks XP7 Automation Director 8.5.202
HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system.
network
high complexity
hpe CWE-287
5.9