Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2017-09-30 CVE-2017-13984 Improper Authentication vulnerability in HP BSM Platform Application Performance Management System Health 9.26/9.30/9.40
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.
network
low complexity
hp CWE-287
6.5
2017-09-30 CVE-2017-13983 Improper Authentication vulnerability in HP BSM Platform Application Performance Management System Health 9.26/9.30/9.40
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to bypass authentication.
network
low complexity
hp CWE-287
critical
9.8
2017-09-29 CVE-2017-12236 Improper Authentication vulnerability in Cisco IOS XE 16.5.1C/3.2.0Ja/3.9.1E
A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks performed when registering an Endpoint Identifier (EID) to a Routing Locator (RLOC) in the map server/map resolver (MS/MR).
network
low complexity
cisco CWE-287
critical
9.8
2017-09-29 CVE-2017-12229 Improper Authentication vulnerability in Cisco IOS XE
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software.
network
low complexity
cisco CWE-287
critical
9.8
2017-09-27 CVE-2017-14766 Improper Authentication vulnerability in Saadamin Simple Student Result
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.
network
low complexity
saadamin CWE-287
7.5
2017-09-26 CVE-2017-5192 Improper Authentication vulnerability in Saltstack Salt
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
network
low complexity
saltstack CWE-287
8.8
2017-09-26 CVE-2017-14602 Improper Authentication vulnerability in Citrix products
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build 41.24) that, if exploited, could allow an attacker with access to the NetScaler management interface to gain administrative access to the appliance.
network
low complexity
citrix CWE-287
7.2
2017-09-22 CVE-2017-14706 Improper Authentication vulnerability in Denyall I-Suite and web Application Firewall
DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken field in the reply.
network
low complexity
denyall CWE-287
critical
9.8
2017-09-22 CVE-2017-14080 Improper Authentication vulnerability in Trendmicro Mobile Security 9.7
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.
network
low complexity
trendmicro CWE-287
critical
9.8
2017-09-21 CVE-2015-1187 Improper Authentication vulnerability in multiple products
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
network
low complexity
dlink trendnet CWE-287
critical
9.8