Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2023-03-02 CVE-2023-0228 Improper Authentication vulnerability in ABB Symphony Plus S+ Operations 2.1/2.2/3.3
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
low complexity
abb CWE-287
8.8
2023-03-01 CVE-2023-25931 Improper Authentication vulnerability in Medtronic Interstim X Clinician and Micro Clinician
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix.
low complexity
medtronic CWE-287
6.8
2023-02-28 CVE-2023-1065 Improper Authentication vulnerability in Snyk Kubernetes Monitor
This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues.
network
low complexity
snyk CWE-287
5.3
2023-02-28 CVE-2023-25264 Improper Authentication vulnerability in Docmosis Tornado
An issue was discovered in Docmosis Tornado prior to version 2.9.5.
network
low complexity
docmosis CWE-287
7.5
2023-02-27 CVE-2023-23493 Improper Authentication vulnerability in Apple Macos
A logic issue was addressed with improved state management.
local
low complexity
apple CWE-287
3.3
2023-02-27 CVE-2022-34908 Improper Authentication vulnerability in Aremis 4 Nomads 1.5.0
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android.
network
low complexity
aremis CWE-287
7.5
2023-02-23 CVE-2023-20012 Improper Authentication vulnerability in Cisco products
A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication.
low complexity
cisco CWE-287
4.6
2023-02-22 CVE-2023-24093 Improper Authentication vulnerability in H3C A210-G Firmware A210Gv100R005
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.
network
low complexity
h3c CWE-287
critical
9.8
2023-02-21 CVE-2015-10083 Improper Authentication vulnerability in Harrys Dynosaur-Rails
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical.
network
low complexity
harrys CWE-287
critical
9.8
2023-02-18 CVE-2023-0905 Improper Authentication vulnerability in Employee Task Management System Project Employee Task Management System 1.0
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0.
7.5