Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-04-25 CVE-2017-12712 Improper Authentication vulnerability in Abbott products
The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications.
low complexity
abbott CWE-287
8.8
2018-04-25 CVE-2018-10362 Improper Authentication vulnerability in PHPliteadmin
An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1.
network
low complexity
phpliteadmin CWE-287
critical
9.8
2018-04-23 CVE-2018-1106 Improper Authentication vulnerability in multiple products
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages.
5.5
2018-04-20 CVE-2014-0927 Improper Authentication vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path.
network
high complexity
ibm CWE-287
8.1
2018-04-20 CVE-2018-6960 Improper Authentication vulnerability in VMWare Horizon Daas 7.0.0
VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication.
network
low complexity
vmware CWE-287
8.8
2018-04-19 CVE-2018-0238 Improper Authentication vulnerability in Cisco Unified Computing System Director 6.5(0.0)/6.5(0.1)
A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal and perform any permitted operations on any virtual machine.
network
low complexity
cisco CWE-287
critical
9.9
2018-04-18 CVE-2018-7760 Improper Authentication vulnerability in Schneider-Electric products
An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200.
network
low complexity
schneider-electric CWE-287
critical
9.8
2018-04-18 CVE-2016-10434 Improper Authentication vulnerability in Qualcomm SD 820 Firmware and SD 820A Firmware
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to RPMB write response function is a buffer from HLOS that needs to be authenticated (using HMAC) and then processed.
network
low complexity
qualcomm CWE-287
7.5
2018-04-17 CVE-2017-2871 Improper Authentication vulnerability in Foscam C1 Firmware 2.52.2.43
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
low complexity
foscam CWE-287
8.8
2018-04-13 CVE-2018-6547 Improper Authentication vulnerability in Plays.Tv
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains an HTTP message parsing function that takes a user-defined path and writes non-user controlled data as SYSTEM to the file when the extract_files parameter is used.
network
low complexity
plays-tv CWE-287
critical
9.1