Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2016-10-06 CVE-2016-6434 Improper Authentication vulnerability in Cisco Firepower Management Center 6.0.1
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
local
low complexity
cisco CWE-287
7.8
2016-10-05 CVE-2016-5686 Improper Authentication vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
network
low complexity
animas CWE-287
critical
9.8
2016-10-05 CVE-2016-5086 Improper Authentication vulnerability in Animas Onetouch Ping Firmware
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
network
low complexity
animas CWE-287
critical
9.8
2016-10-03 CVE-2016-7141 Improper Authentication vulnerability in multiple products
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
network
low complexity
opensuse haxx CWE-287
7.5
2016-09-28 CVE-2016-7191 Improper Authentication vulnerability in Microsoft Azure Active Directory Passport
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.
network
high complexity
microsoft CWE-287
8.1
2016-09-21 CVE-2016-6159 Improper Authentication vulnerability in Huawei Ws331A Router Firmware Ws331A10V100R001C02B017Sp01
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special packages" to the LAN interface.
high complexity
huawei CWE-287
7.5
2016-09-21 CVE-2016-4966 Improper Authentication vulnerability in Fortinet Fortiwan
The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter.
network
low complexity
fortinet CWE-287
6.5
2016-09-19 CVE-2016-4860 Improper Authentication vulnerability in Yokogawa Stardom Fcn/Fcj
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.
network
low complexity
yokogawa CWE-287
7.3
2016-09-18 CVE-2016-0883 Improper Authentication vulnerability in Pivotal Software Operations Manager
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
network
low complexity
pivotal-software CWE-287
critical
9.8
2016-09-06 CVE-2016-7114 Improper Authentication vulnerability in Siemens En100 Ethernet Module Firmware 4.28
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.87; SIPROTEC 7UT686 : All versions < V 4.02; SIPROTEC 7SD686 : All versions < V 4.05; SIPROTEC 7SJ66 : All versions < V 4.30.
network
low complexity
siemens CWE-287
8.8