Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2017-05-06 CVE-2017-7921 Improper Authentication vulnerability in Hikvision products
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices.
network
low complexity
hikvision CWE-287
critical
10.0
2017-05-06 CVE-2017-7909 Improper Authentication vulnerability in Advantech B+B Smartworx Mesr901 Firmware 1.5.2
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior.
network
low complexity
advantech-b-b-smartworx CWE-287
critical
9.8
2017-05-03 CVE-2017-6624 Improper Authentication vulnerability in Cisco IOS 15.5(3)M
A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls.
network
low complexity
cisco CWE-287
5.3
2017-05-01 CVE-2017-8403 Improper Authentication vulnerability in 360Fly 4K Camera Firmware 2.1.4
360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password.
low complexity
360fly CWE-287
8.8
2017-04-28 CVE-2017-2101 Improper Authentication vulnerability in IPA Appgoat 3.0.0
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arbitrary operations via unspecified vectors.
network
low complexity
ipa CWE-287
7.3
2017-04-25 CVE-2017-8223 Improper Authentication vulnerability in Wificam Wireless IP Camera (P2P) Firmware
On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.
network
low complexity
wificam CWE-287
7.5
2017-04-24 CVE-2017-2332 Improper Authentication vulnerability in Juniper Northstar Controller 2.1.0
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control over the environment.
network
low complexity
juniper CWE-287
8.8
2017-04-24 CVE-2017-2329 Improper Authentication vulnerability in Juniper Northstar Controller 2.1.0
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing widespread denials of system services.
local
low complexity
juniper CWE-287
6.2
2017-04-24 CVE-2017-2319 Improper Authentication vulnerability in Juniper Northstar Controller 2.1.0
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and systems as a result.
network
low complexity
juniper CWE-287
8.3
2017-04-23 CVE-2017-8078 Improper Authentication vulnerability in Tp-Link Tl-Sg108E Firmware 1.1.2
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd).
network
low complexity
tp-link CWE-287
5.3