Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2017-04-24 CVE-2017-2329 Improper Authentication vulnerability in Juniper Northstar Controller 2.1.0
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing widespread denials of system services.
local
low complexity
juniper CWE-287
6.2
2017-04-24 CVE-2017-2319 Improper Authentication vulnerability in Juniper Northstar Controller 2.1.0
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and systems as a result.
network
low complexity
juniper CWE-287
8.3
2017-04-23 CVE-2017-8078 Improper Authentication vulnerability in Tp-Link Tl-Sg108E Firmware 1.1.2
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd).
network
low complexity
tp-link CWE-287
5.3
2017-04-20 CVE-2017-6617 Improper Authentication vulnerability in Cisco Integrated Management Controller Supervisor 3.0(1C)
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
network
low complexity
cisco CWE-287
5.4
2017-04-20 CVE-2016-1219 Improper Authentication vulnerability in Cybozu Garoon
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.
network
low complexity
cybozu CWE-287
critical
9.8
2017-04-19 CVE-2016-5410 Improper Authentication vulnerability in multiple products
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
local
low complexity
firewalld redhat CWE-287
5.5
2017-04-12 CVE-2017-7284 Improper Authentication vulnerability in Unitrends Enterprise Backup
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password.
network
low complexity
unitrends CWE-287
8.8
2017-04-12 CVE-2017-7588 Improper Authentication vulnerability in Brother products
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt.
network
low complexity
brother CWE-287
critical
9.8
2017-04-11 CVE-2016-1908 Improper Authentication vulnerability in multiple products
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.
network
low complexity
openbsd debian oracle redhat CWE-287
critical
9.8
2017-04-10 CVE-2016-5068 Improper Authentication vulnerability in Sierrawireless Aleos Firmware 4.3.2
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.
network
low complexity
sierrawireless CWE-287
critical
9.8