Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-12-07 CVE-2021-43175 Improper Authentication vulnerability in Goautodial and Goautodial API
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions.
network
low complexity
goautodial CWE-287
7.5
2021-12-07 CVE-2021-37043 Improper Authentication vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious application processes occupy system resources.
network
low complexity
huawei CWE-287
7.5
2021-12-07 CVE-2021-37100 Improper Authentication vulnerability in Huawei Harmonyos
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.
network
low complexity
huawei CWE-287
7.5
2021-12-06 CVE-2021-39890 Improper Authentication vulnerability in Gitlab
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
network
low complexity
gitlab CWE-287
critical
9.8
2021-12-06 CVE-2021-43931 Improper Authentication vulnerability in Webhmi Firmware 3.5/4.0
The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
network
low complexity
webhmi CWE-287
critical
9.8
2021-11-23 CVE-2021-35033 Improper Authentication vulnerability in Zyxel products
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
local
low complexity
zyxel CWE-287
7.8
2021-11-22 CVE-2021-38376 Improper Authentication vulnerability in Open-Xchange OX APP Suite 7.10.5
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
network
low complexity
open-xchange CWE-287
5.3
2021-11-20 CVE-2021-36308 Improper Authentication vulnerability in Dell Networking Os10
Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2021-11-17 CVE-2021-0096 Improper Authentication vulnerability in Intel products
Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
7.8
2021-11-17 CVE-2021-33087 Improper Authentication vulnerability in Intel NUC M15 Laptop KIT Management Engine Driver Pack
Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-287
5.5