Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-34786 Improper Authentication vulnerability in Cisco Broadworks Commpilot Application Software
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
network
low complexity
cisco CWE-287
4.9
2021-09-08 CVE-2021-30605 Improper Authentication vulnerability in Google Chrome OS Readiness Tool 1.0.0.0/1.0.1.0
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
local
low complexity
google CWE-287
7.8
2021-09-08 CVE-2021-1863 Improper Authentication vulnerability in Apple Iphone OS
An issue existed with authenticating the action triggered by an NFC tag.
low complexity
apple CWE-287
2.4
2021-09-08 CVE-2021-30667 Improper Authentication vulnerability in Apple Iphone OS
A logic issue was addressed with improved validation.
low complexity
apple CWE-287
5.4
2021-09-08 CVE-2021-30668 Improper Authentication vulnerability in Apple Macos
This issue was addressed with improved checks.
low complexity
apple CWE-287
4.6
2021-09-08 CVE-2021-30702 Improper Authentication vulnerability in Apple mac OS X and Macos
A logic issue was addressed with improved state management.
low complexity
apple CWE-287
4.6
2021-09-08 CVE-2021-30720 Improper Authentication vulnerability in Apple products
A logic issue was addressed with improved restrictions.
network
low complexity
apple CWE-287
5.4
2021-09-08 CVE-2021-30769 Improper Authentication vulnerability in Apple Watchos
A logic issue was addressed with improved state management.
local
low complexity
apple CWE-287
5.5
2021-09-08 CVE-2021-30770 Improper Authentication vulnerability in Apple Watchos
A logic issue was addressed with improved validation.
local
low complexity
apple CWE-287
5.5
2021-09-08 CVE-2020-11264 Improper Authentication vulnerability in Qualcomm products
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
network
low complexity
qualcomm CWE-287
critical
9.8