Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2013-08-20 CVE-2013-2157 Improper Authentication vulnerability in Openstack Keystone
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
network
openstack CWE-287
4.3
2013-08-09 CVE-2013-3659 Improper Authentication vulnerability in Nttdocomo Overseas Usage 2.0.0/2.0.4
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area.
low complexity
nttdocomo CWE-287
3.3
2013-08-01 CVE-2013-2993 Improper Authentication vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.
network
ibm CWE-287
5.8
2013-07-31 CVE-2013-2056 Improper Authentication vulnerability in Redhat Satellite 5.3/5.4/5.5
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
network
low complexity
redhat CWE-287
5.0
2013-07-29 CVE-2013-2245 Improper Authentication vulnerability in Moodle
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
network
low complexity
moodle CWE-287
4.0
2013-07-25 CVE-2013-3431 Improper Authentication vulnerability in Cisco Video Surveillance Manager
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.
network
low complexity
cisco CWE-287
7.8
2013-07-25 CVE-2013-3430 Improper Authentication vulnerability in Cisco Video Surveillance Manager
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.
network
low complexity
cisco CWE-287
critical
9.0
2013-07-20 CVE-2013-3656 Improper Authentication vulnerability in Cybozu Office
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
network
cybozu CWE-287
5.8
2013-07-18 CVE-2013-4877 Improper Authentication vulnerability in Verizon Wireless Network Extender Scs26Uc4/Scs2U01
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.
local
high complexity
verizon CWE-287
2.6
2013-07-18 CVE-2013-4875 Improper Authentication vulnerability in Verizon Wireless Network Extender Scs2U01
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI cable and sending a SysReq interrupt.
local
high complexity
verizon CWE-287
6.2