Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-09-14 CVE-2018-16286 Improper Authentication vulnerability in LG Supersign CMS
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
network
low complexity
lg CWE-287
critical
9.8
2018-09-12 CVE-2018-7572 Improper Authentication vulnerability in Pulsesecure Pulse Secure Desktop
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client.
low complexity
pulsesecure CWE-287
6.8
2018-09-12 CVE-2018-1773 Improper Authentication vulnerability in IBM Datacap 9.1.1/9.1.3/9.1.4
IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed.
network
low complexity
ibm CWE-287
4.3
2018-09-12 CVE-2018-16947 Improper Authentication vulnerability in multiple products
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
network
low complexity
openafs debian CWE-287
critical
9.8
2018-09-07 CVE-2018-15485 Improper Authentication vulnerability in Kone Group Controller Firmware
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5.
network
low complexity
kone CWE-287
critical
9.1
2018-09-06 CVE-2018-16590 Improper Authentication vulnerability in Furuno Felcom 250 Firmware and Felcom 500 Firmware
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
network
low complexity
furuno CWE-287
critical
9.8
2018-09-06 CVE-2017-14026 Improper Authentication vulnerability in Iceqube Thermal Management Center Firmware 3.18
In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an attacker to gain access to sensitive information.
network
low complexity
iceqube CWE-287
7.5
2018-08-30 CVE-2018-15479 Improper Authentication vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
low complexity
mystrom CWE-287
6.5
2018-08-30 CVE-2018-15478 Improper Authentication vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
high complexity
mystrom CWE-287
8.1
2018-08-30 CVE-2018-13821 Improper Authentication vulnerability in CA Unified Infrastructure Management 8.4.7/8.5/8.5.1
A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.
network
low complexity
ca CWE-287
critical
9.8