Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-10-21 CVE-2022-26870 Improper Authentication vulnerability in Dell Powerstoreos 2.1.0.0/2.1.0.1
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2022-10-21 CVE-2022-43400 Improper Authentication vulnerability in Siemens Siveillance Video Mobile Server
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)).
network
low complexity
siemens CWE-287
critical
9.8
2022-10-20 CVE-2022-42233 Improper Authentication vulnerability in Tenda 11N Firmware 5.07.33Cn
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
network
low complexity
tenda CWE-287
critical
9.8
2022-10-20 CVE-2022-37298 Improper Authentication vulnerability in Shinken-Monitoring Shinken Monitoring 2.4.3
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control.
network
low complexity
shinken-monitoring CWE-287
critical
9.8
2022-10-19 CVE-2022-39267 Improper Authentication vulnerability in Xbifrost Bifrost
Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments.
network
low complexity
xbifrost CWE-287
8.8
2022-10-18 CVE-2022-40684 Improper Authentication vulnerability in Fortinet Fortios, Fortiproxy and Fortiswitchmanager
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
network
low complexity
fortinet CWE-287
critical
9.8
2022-10-18 CVE-2022-31122 Improper Authentication vulnerability in Wire Server
Wire is an encrypted communication and collaboration platform.
network
high complexity
wire CWE-287
8.1
2022-10-18 CVE-2022-22237 Improper Authentication vulnerability in Juniper Junos
An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity.
network
low complexity
juniper CWE-287
6.5
2022-10-17 CVE-2022-23769 Improper Authentication vulnerability in Megazone Reversewall-Mds 3.8A007
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS.
network
low complexity
megazone CWE-287
critical
9.8
2022-10-17 CVE-2022-2533 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
high complexity
gitlab CWE-287
7.4