Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2023-40260 Improper Authentication vulnerability in Empowerid 7.205.0.0
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes to the new email address (which may be attacker-controlled).
network
low complexity
empowerid CWE-287
critical
9.1
2023-08-08 CVE-2023-21626 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
local
low complexity
qualcomm CWE-287
7.1
2023-08-07 CVE-2023-32090 Improper Authentication vulnerability in Pega Platform
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
network
low complexity
pega CWE-287
critical
9.8
2023-08-04 CVE-2023-0264 Improper Authentication vulnerability in Redhat products
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests.
network
high complexity
redhat CWE-287
5.0
2023-08-04 CVE-2023-38691 Improper Authentication vulnerability in Matrix Matrix-Appservice-Bridge
matrix-appservice-bridge provides an API for setting up bridges.
network
low complexity
matrix CWE-287
6.5
2023-08-04 CVE-2023-39112 Improper Authentication vulnerability in Shopex Ecshop 4.1.16
ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
network
low complexity
shopex CWE-287
6.5
2023-08-03 CVE-2023-20214 Improper Authentication vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient request validation when using the REST API feature.
network
low complexity
cisco CWE-287
critical
9.1
2023-08-03 CVE-2023-33363 Improper Authentication vulnerability in Supremainc Biostar 2
An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.
network
low complexity
supremainc CWE-287
7.5
2023-08-03 CVE-2023-34196 Improper Authentication vulnerability in Keyfactor Ejbca
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue.
network
low complexity
keyfactor CWE-287
8.2
2023-08-02 CVE-2023-1935 Improper Authentication vulnerability in Emerson products
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.
network
low complexity
emerson CWE-287
critical
9.4