Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2018-01-10 CVE-2018-0008 Improper Authentication vulnerability in Juniper Junos
An unauthenticated root login may allow upon reboot when a commit script is used.
low complexity
juniper CWE-287
6.2
2018-01-10 CVE-2017-3765 Improper Authentication vulnerability in Lenovo Enterprise Network Operating System 8.4.0.0
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console, Telnet, SSH, and Web interfaces.
local
high complexity
lenovo CWE-287
7.0
2018-01-09 CVE-2017-12695 Improper Authentication vulnerability in GM Shanghai Onstar 7.1
An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1.
network
low complexity
gm CWE-287
8.8
2018-01-08 CVE-2017-15883 Improper Authentication vulnerability in Progress Sitefinity
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
network
low complexity
progress CWE-287
critical
9.8
2018-01-08 CVE-2018-3815 Improper Authentication vulnerability in Stalker Communigate PRO 6.2
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address.
network
low complexity
stalker CWE-287
5.7
2018-01-05 CVE-2017-15548 Improper Authentication vulnerability in EMC products
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0.
network
low complexity
emc CWE-287
critical
9.8
2018-01-03 CVE-2017-1000489 Improper Authentication vulnerability in multiple products
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
network
high complexity
mautic acquia CWE-287
8.1
2018-01-02 CVE-2017-1000433 Improper Authentication vulnerability in multiple products
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled.
network
high complexity
pysaml2-project debian CWE-287
8.1
2018-01-01 CVE-2018-3810 Improper Authentication vulnerability in Oturia Smart Google Code Inserter
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress.
network
low complexity
oturia CWE-287
critical
9.8
2017-12-29 CVE-2014-0121 Improper Authentication vulnerability in multiple products
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
network
low complexity
hawt redhat CWE-287
critical
9.8