Vulnerabilities > Improper Authentication
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-09 | CVE-2021-25451 | Improper Authentication vulnerability in Google Android 10.0/11.0/9.0 A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data. | 3.3 |
2021-09-09 | CVE-2021-25466 | Improper Authentication vulnerability in Samsung Internet Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token. | 5.9 |
2021-09-09 | CVE-2021-39296 | Improper Authentication vulnerability in Openbmc-Project Openbmc 2.9.0 In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. | 10.0 |
2021-09-09 | CVE-2021-28493 | Improper Authentication vulnerability in Arista Metamako Operating System In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. | 7.8 |
2021-09-09 | CVE-2021-28494 | Improper Authentication vulnerability in Arista Metamako Operating System In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. | 8.8 |
2021-09-09 | CVE-2021-28495 | Improper Authentication vulnerability in Arista Metamako Operating System In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. | 9.8 |
2021-09-09 | CVE-2021-34785 | Improper Authentication vulnerability in Cisco Broadworks Commpilot Application Software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. | 7.2 |
2021-09-09 | CVE-2021-34786 | Improper Authentication vulnerability in Cisco Broadworks Commpilot Application Software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. | 4.9 |
2021-09-08 | CVE-2021-30605 | Improper Authentication vulnerability in Google Chrome OS Readiness Tool 1.0.0.0/1.0.1.0 Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls. | 7.8 |
2021-09-08 | CVE-2021-1863 | Improper Authentication vulnerability in Apple Iphone OS An issue existed with authenticating the action triggered by an NFC tag. | 2.4 |