Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-5970 Improper Authentication vulnerability in Sonicwall products
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
network
low complexity
sonicwall CWE-287
8.8
2023-12-05 CVE-2023-47304 Improper Authentication vulnerability in Vonage Vdv23 Firmware Vdv213.2.110.5.1
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
local
low complexity
vonage CWE-287
7.8
2023-12-05 CVE-2023-33054 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
network
low complexity
qualcomm CWE-287
critical
9.1
2023-12-05 CVE-2023-33070 Improper Authentication vulnerability in Qualcomm products
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
local
low complexity
qualcomm CWE-287
5.5
2023-12-05 CVE-2023-42576 Improper Authentication vulnerability in Samsung Pass 4.0.05.1/4.2.03.1
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
low complexity
samsung CWE-287
6.8
2023-12-05 CVE-2023-5808 Improper Authentication vulnerability in Hitachi Vantara Hitachi Network Attached Storage
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation.
network
low complexity
hitachi CWE-287
6.5
2023-12-04 CVE-2023-44302 Improper Authentication vulnerability in Dell Powerprotect Data Manager Dm5500 Firmware
Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2023-11-30 CVE-2023-6342 Improper Authentication vulnerability in Tylertech Court Case Management Plus
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters.
network
low complexity
tylertech CWE-287
critical
9.8
2023-11-30 CVE-2023-6343 Improper Authentication vulnerability in Tylertech Court Case Management Plus
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters.
network
low complexity
tylertech CWE-287
5.3
2023-11-30 CVE-2023-6344 Improper Authentication vulnerability in Tylertech Court Case Management Plus
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter.
network
low complexity
tylertech CWE-287
5.3