Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-01-29 CVE-2017-1000354 Improper Authentication vulnerability in Jenkins
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user.
network
low complexity
jenkins CWE-287
8.8
2018-01-29 CVE-2017-1783 Improper Authentication vulnerability in multiple products
IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication.
local
low complexity
ibm netapp CWE-287
4.0
2018-01-29 CVE-2017-14698 Improper Authentication vulnerability in Asus products
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote attackers to change passwords of arbitrary users via the http_passwd parameter to mod_login.asp.
network
low complexity
asus CWE-287
critical
9.8
2018-01-24 CVE-2017-15135 Improper Authentication vulnerability in Fedoraproject 389 Directory Server
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process.
network
high complexity
fedoraproject CWE-287
8.1
2018-01-23 CVE-2017-15531 Improper Authentication vulnerability in Symantec Reporter 10.1/9.5
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users.
network
low complexity
symantec CWE-287
critical
9.8
2018-01-23 CVE-2017-16590 Improper Authentication vulnerability in Netgain-Systems Enterprise Manager 7.2.699
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1001.
network
low complexity
netgain-systems CWE-287
8.8
2018-01-19 CVE-2015-6926 Improper Authentication vulnerability in Oxid-Esales Eshop
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.
network
low complexity
oxid-esales CWE-287
7.5
2018-01-15 CVE-2018-5328 Improper Authentication vulnerability in Beims Contractorweb.Net 5.18.0.0
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details.
network
low complexity
beims CWE-287
critical
9.8
2018-01-12 CVE-2014-6436 Improper Authentication vulnerability in Aztech products
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
network
low complexity
aztech CWE-287
critical
9.8
2018-01-12 CVE-2014-6435 Improper Authentication vulnerability in Aztech products
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request.
network
low complexity
aztech CWE-287
7.5