Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-30770 Improper Authentication vulnerability in Apple Watchos
A logic issue was addressed with improved validation.
local
low complexity
apple CWE-287
5.5
2021-09-08 CVE-2020-11264 Improper Authentication vulnerability in Qualcomm products
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
network
low complexity
qualcomm CWE-287
critical
9.8
2021-09-08 CVE-2020-11301 Improper Authentication vulnerability in Qualcomm products
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-287
7.5
2021-09-02 CVE-2021-34746 Improper Authentication vulnerability in Cisco Enterprise NFV Infrastructure Software
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator.
network
low complexity
cisco CWE-287
critical
9.8
2021-09-01 CVE-2021-40350 Improper Authentication vulnerability in Christiedigital Dwu850-Gs Firmware 06.46
webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspecified Cookie header.
network
low complexity
christiedigital CWE-287
critical
9.8
2021-08-31 CVE-2021-22002 Improper Authentication vulnerability in VMWare products
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header.
network
low complexity
vmware CWE-287
critical
9.8
2021-08-31 CVE-2021-22943 Improper Authentication vulnerability in UI Unifi Protect 1.13.3
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network.
low complexity
ui CWE-287
critical
9.6
2021-08-30 CVE-2021-36370 Improper Authentication vulnerability in Midnight-Commander Midnight Commander
An issue was discovered in Midnight Commander through 4.8.26.
network
low complexity
midnight-commander CWE-287
7.5
2021-08-30 CVE-2021-37417 Improper Authentication vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
network
low complexity
zohocorp CWE-287
critical
9.8
2021-08-30 CVE-2021-22025 Improper Authentication vulnerability in VMWare products
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access.
network
low complexity
vmware CWE-287
7.5