Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-12-15 CVE-2021-43935 Improper Authentication vulnerability in Baxter products
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability.
network
low complexity
baxter CWE-287
critical
9.8
2021-12-14 CVE-2021-44937 Improper Authentication vulnerability in Glfusion 1.7.9
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php.
network
low complexity
glfusion CWE-287
5.3
2021-12-14 CVE-2021-44524 Improper Authentication vulnerability in Siemens Sipass Integrated and Siveillance Identity
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0).
network
low complexity
siemens CWE-287
critical
9.8
2021-12-13 CVE-2021-39064 Improper Authentication vulnerability in IBM Spectrum Copy Data Management 2.2.0.0/2.2.13
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console.
network
low complexity
ibm CWE-287
7.5
2021-12-09 CVE-2021-44514 Improper Authentication vulnerability in Zohocorp Manageengine Opmanager 12.5
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
network
low complexity
zohocorp CWE-287
critical
9.8
2021-12-09 CVE-2021-20145 Improper Authentication vulnerability in Gryphonconnect Gryphon Tower Firmware
Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service.
network
low complexity
gryphonconnect CWE-287
7.5
2021-12-09 CVE-2021-21955 Improper Authentication vulnerability in Anker Eufy Homebase 2 Firmware 2.1.6.9H
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.
network
low complexity
anker CWE-287
7.5
2021-12-09 CVE-2021-43068 Improper Authentication vulnerability in Fortinet Fortiauthenticator 6.4.0
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
network
low complexity
fortinet CWE-287
8.1
2021-12-08 CVE-2021-36718 Improper Authentication vulnerability in Synel Eharmonynew and Synel Reports
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11.
network
low complexity
synel CWE-287
6.5
2021-12-08 CVE-2021-37054 Improper Authentication vulnerability in Huawei Emui, Harmonyos and Magic UI
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-287
7.5