Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2016-05-31 CVE-2016-2286 Improper Authentication vulnerability in Moxa products
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a blank default password, which allows remote attackers to obtain access via unspecified vectors.
network
low complexity
moxa CWE-287
7.5
2016-05-07 CVE-2016-2012 Improper Authentication vulnerability in HP Network Node Manager I
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.
network
low complexity
hp CWE-287
6.5
2016-05-06 CVE-2016-4422 Improper Authentication vulnerability in multiple products
The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.
network
low complexity
libpam-sshauth-project debian CWE-287
critical
9.8
2016-05-05 CVE-2016-1387 Improper Authentication vulnerability in Cisco Telepresence TC Software
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute control commands or make configuration changes via an API request, aka Bug ID CSCuz26935.
network
low complexity
cisco CWE-287
critical
9.8
2016-04-22 CVE-2016-2300 Improper Authentication vulnerability in Ecava Integraxor
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
network
low complexity
ecava CWE-287
6.5
2016-04-15 CVE-2016-2076 Improper Authentication vulnerability in VMWare products
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
network
low complexity
vmware CWE-287
7.6
2016-04-12 CVE-2016-0733 Improper Authentication vulnerability in Apache Ranger 0.4.0/0.4.1/0.5.0
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.
network
low complexity
apache CWE-287
critical
9.8
2016-03-19 CVE-2016-2245 Improper Authentication vulnerability in HP Support Assistant 8.1.40.3
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.
network
low complexity
hp CWE-287
critical
9.8
2016-03-03 CVE-2016-1329 Improper Authentication vulnerability in multiple products
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.
network
low complexity
samsung sun zyxel zzinc CWE-287
critical
9.8
2016-02-04 CVE-2015-8269 Improper Authentication vulnerability in Fisher-Price Smart TOY Bear
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
network
high complexity
fisher-price CWE-287
7.5