Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-06-16 CVE-2018-18907 Improper Authentication vulnerability in Dlink Dir-850L Firmare
An issue was discovered on D-Link DIR-850L 1.21WW devices.
network
low complexity
dlink CWE-287
7.5
2022-06-16 CVE-2022-33750 Improper Authentication vulnerability in Broadcom CA Automic Automation 12.2/12.3
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.
network
low complexity
broadcom CWE-287
critical
9.8
2022-06-16 CVE-2022-29865 Improper Authentication vulnerability in Opcfoundation UA .Net Standard Stack
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
network
low complexity
opcfoundation CWE-287
7.5
2022-06-15 CVE-2022-30150 Improper Authentication vulnerability in Microsoft products
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
network
high complexity
microsoft CWE-287
7.5
2022-06-15 CVE-2022-21935 Improper Authentication vulnerability in Johnsoncontrols products
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
network
low complexity
johnsoncontrols CWE-287
7.5
2022-06-15 CVE-2022-20798 Improper Authentication vulnerability in Cisco products
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface of an affected device.
network
low complexity
cisco CWE-287
critical
9.8
2022-06-14 CVE-2021-35094 Improper Authentication vulnerability in Qualcomm products
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-287
7.8
2022-06-14 CVE-2022-30229 Improper Authentication vulnerability in Siemens Sicam Gridedge Essential
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6), SICAM GridEdge Essential Intel (All versions < V2.6.6), SICAM GridEdge Essential with GDS ARM (All versions < V2.6.6), SICAM GridEdge Essential with GDS Intel (All versions < V2.6.6).
network
low complexity
siemens CWE-287
5.3
2022-06-13 CVE-2022-22259 Improper Authentication vulnerability in Huawei Flmg-10 Firmware 10.0.1.0(H100Sp22C00)
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00).
low complexity
huawei CWE-287
6.8
2022-06-07 CVE-2022-30749 Improper Authentication vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.
local
low complexity
samsung CWE-287
7.8