Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2017-10-13 CVE-2017-10623 Improper Authentication vulnerability in Juniper Junos Space
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes.
network
high complexity
juniper CWE-287
8.1
2017-10-13 CVE-2017-10622 Improper Authentication vulnerability in Juniper Junos Space 16.1/17.1
An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user.
network
low complexity
juniper CWE-287
critical
9.8
2017-10-13 CVE-2016-5791 Improper Authentication vulnerability in Jantek Jtc-200 Firmware
An Improper Authentication issue was discovered in JanTek JTC-200, all versions.
network
low complexity
jantek CWE-287
critical
9.8
2017-10-11 CVE-2017-5791 Improper Authentication vulnerability in HP Intelligent Management Center Plat 7.2
The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.
network
low complexity
hp CWE-287
critical
9.8
2017-10-11 CVE-2017-14003 Improper Authentication vulnerability in Lavalink Ether-Serial Link Firmware 6.01.00/29.03.2007
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions.
network
low complexity
lavalink CWE-287
critical
9.8
2017-10-09 CVE-2017-14972 Improper Authentication vulnerability in Infocus Mondopad 2.2.08
InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file.
network
low complexity
infocus CWE-287
7.5
2017-10-05 CVE-2016-8937 Improper Authentication vulnerability in IBM Tivoli Storage Manager
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication.
network
low complexity
ibm CWE-287
critical
9.8
2017-10-05 CVE-2017-14000 Improper Authentication vulnerability in Ctekproducts Skyrouter Z4200 Firmware and Skyrouter Z4400 Firmware
An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11.
network
low complexity
ctekproducts CWE-287
critical
9.4
2017-10-05 CVE-2017-13995 Improper Authentication vulnerability in Spidercontrol Ininet Webserver
An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100.
network
low complexity
spidercontrol CWE-287
critical
10.0
2017-10-05 CVE-2017-1000110 Improper Authentication vulnerability in Jenkins Blue Ocean
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins.
network
low complexity
jenkins CWE-287
4.3