Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2023-09-15 CVE-2023-41900 Improper Authentication vulnerability in multiple products
Jetty is a Java based web server and servlet engine.
network
low complexity
eclipse debian CWE-287
4.3
2023-09-15 CVE-2023-42442 Improper Authentication vulnerability in Fit2Cloud Jumpserver
JumpServer is an open source bastion host and a professional operation and maintenance security audit system.
network
low complexity
fit2cloud CWE-287
5.3
2023-09-15 CVE-2022-47848 Improper Authentication vulnerability in Bezeq Vtech Iad604-Il Firmware and Vtech Nb403-Il Firmware
An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of the UPnP service.
network
low complexity
bezeq CWE-287
7.5
2023-09-14 CVE-2023-4669 Improper Authentication vulnerability in Exagate Sysguard 3001 Firmware
Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass.This issue affects SYSGuard 3001: before 3.2.20.0.
network
low complexity
exagate CWE-287
critical
9.8
2023-09-13 CVE-2023-4568 Improper Authentication vulnerability in Papercut NG
PaperCut NG allows for unauthenticated XMLRPC commands to be run by default.
network
low complexity
papercut CWE-287
6.5
2023-09-12 CVE-2023-39215 Improper Authentication vulnerability in Zoom Meeting Software Development KIT and Zoom
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
network
low complexity
zoom CWE-287
6.5
2023-09-12 CVE-2023-4501 Improper Authentication vulnerability in Microfocus products
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations.
network
low complexity
microfocus CWE-287
critical
9.8
2023-09-12 CVE-2023-29463 Improper Authentication vulnerability in Rockwellautomation Pavilion8
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication.
network
low complexity
rockwellautomation CWE-287
5.4
2023-09-11 CVE-2023-39069 Improper Authentication vulnerability in Strangebee Cortex and Thehive
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
network
low complexity
strangebee CWE-287
critical
9.8
2023-09-11 CVE-2023-4816 Improper Authentication vulnerability in Hitachienergy Asset Suite
A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214.
network
low complexity
hitachienergy CWE-287
8.8