Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-11-11 CVE-2022-26845 Improper Authentication vulnerability in Intel Active Management Technology Firmware
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-287
critical
9.8
2022-11-11 CVE-2022-27874 Improper Authentication vulnerability in Intel XMM 7560 Firmware
Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.
low complexity
intel CWE-287
7.2
2022-11-11 CVE-2022-29893 Improper Authentication vulnerability in Intel Active Management Technology Firmware
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-287
8.8
2022-11-11 CVE-2022-36370 Improper Authentication vulnerability in Intel products
Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
7.8
2022-11-11 CVE-2022-37345 Improper Authentication vulnerability in Intel products
Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
7.8
2022-11-10 CVE-2022-39038 Improper Authentication vulnerability in Flowring Agentflow 4.0.0.1183.552
Agentflow BPM enterprise management system has improper authentication.
network
low complexity
flowring CWE-287
8.8
2022-11-09 CVE-2022-39892 Improper Authentication vulnerability in Samsung Pass
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.
network
low complexity
samsung CWE-287
critical
9.8
2022-11-09 CVE-2022-44244 Improper Authentication vulnerability in Lin-Cms Project Lin-Cms 0.2.1
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
network
high complexity
lin-cms-project CWE-287
6.6
2022-11-08 CVE-2022-27510 Improper Authentication vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Unauthorized access to Gateway user capabilities
network
low complexity
citrix CWE-287
critical
9.8
2022-11-04 CVE-2022-39387 Improper Authentication vulnerability in Xwiki Openid Connect
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki.
network
low complexity
xwiki CWE-287
7.5