Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-39296 Improper Authentication vulnerability in Openbmc-Project Openbmc 2.9.0
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
network
low complexity
openbmc-project CWE-287
critical
10.0
2021-09-09 CVE-2021-28493 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so.
local
low complexity
arista CWE-287
7.8
2021-09-09 CVE-2021-28494 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI.
network
low complexity
arista CWE-287
8.8
2021-09-09 CVE-2021-28495 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs.
network
low complexity
arista CWE-287
critical
9.8
2021-09-09 CVE-2021-34785 Improper Authentication vulnerability in Cisco Broadworks Commpilot Application Software
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
network
low complexity
cisco CWE-287
7.2
2021-09-09 CVE-2021-34786 Improper Authentication vulnerability in Cisco Broadworks Commpilot Application Software
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
network
low complexity
cisco CWE-287
4.9
2021-09-08 CVE-2021-30605 Improper Authentication vulnerability in Google Chrome OS Readiness Tool 1.0.0.0/1.0.1.0
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
local
low complexity
google CWE-287
7.8
2021-09-08 CVE-2021-1863 Improper Authentication vulnerability in Apple Iphone OS
An issue existed with authenticating the action triggered by an NFC tag.
low complexity
apple CWE-287
2.4
2021-09-08 CVE-2021-30667 Improper Authentication vulnerability in Apple Iphone OS
A logic issue was addressed with improved validation.
low complexity
apple CWE-287
5.4
2021-09-08 CVE-2021-30668 Improper Authentication vulnerability in Apple Macos
This issue was addressed with improved checks.
low complexity
apple CWE-287
4.6