Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-11-15 CVE-2022-25667 Improper Authentication vulnerability in Qualcomm products
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-287
7.5
2022-11-14 CVE-2022-3477 Improper Authentication vulnerability in multiple products
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
9.8
2022-11-11 CVE-2022-34331 Improper Authentication vulnerability in IBM Powervm Hypervisor Fw1010/Fw950
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled.
network
low complexity
ibm CWE-287
critical
9.8
2022-11-11 CVE-2021-33159 Improper Authentication vulnerability in Intel Active Management Technology Firmware
Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
6.7
2022-11-11 CVE-2022-21794 Improper Authentication vulnerability in Intel products
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
6.7
2022-11-11 CVE-2022-26508 Improper Authentication vulnerability in Intel Server Debug and Provisioning Tool
Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-287
7.5
2022-11-11 CVE-2022-26845 Improper Authentication vulnerability in Intel Active Management Technology Firmware
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-287
critical
9.8
2022-11-11 CVE-2022-27874 Improper Authentication vulnerability in Intel XMM 7560 Firmware
Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.
low complexity
intel CWE-287
7.2
2022-11-11 CVE-2022-29893 Improper Authentication vulnerability in Intel Active Management Technology Firmware
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-287
8.8
2022-11-11 CVE-2022-36370 Improper Authentication vulnerability in Intel products
Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
7.8