Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-09-15 CVE-2021-33700 Improper Authentication vulnerability in SAP Business ONE 10.0
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password.
local
low complexity
sap CWE-287
7.8
2021-09-10 CVE-2021-3145 Improper Authentication vulnerability in Ionic Identity Vault
In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
local
low complexity
ionic CWE-287
6.7
2021-09-10 CVE-2021-37414 Improper Authentication vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
network
low complexity
zohocorp CWE-287
7.5
2021-09-09 CVE-2021-25451 Improper Authentication vulnerability in Google Android 10.0/11.0/9.0
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
local
low complexity
google CWE-287
3.3
2021-09-09 CVE-2021-25466 Improper Authentication vulnerability in Samsung Internet
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
network
high complexity
samsung CWE-287
5.9
2021-09-09 CVE-2021-39296 Improper Authentication vulnerability in Openbmc-Project Openbmc 2.9.0
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
network
low complexity
openbmc-project CWE-287
critical
10.0
2021-09-09 CVE-2021-28493 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so.
local
low complexity
arista CWE-287
7.8
2021-09-09 CVE-2021-28494 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI.
network
low complexity
arista CWE-287
8.8
2021-09-09 CVE-2021-28495 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs.
network
low complexity
arista CWE-287
critical
9.8
2021-09-09 CVE-2021-34785 Improper Authentication vulnerability in Cisco Broadworks Commpilot Application Software
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
network
low complexity
cisco CWE-287
7.2