Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2020-26558 Improper Authentication vulnerability in multiple products
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session.
4.2
2021-05-17 CVE-2021-27734 Improper Authentication vulnerability in Belden Hirschmann Hios and Hisecos
Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.
network
low complexity
belden CWE-287
critical
9.8
2021-05-16 CVE-2021-29047 Improper Authentication vulnerability in Liferay DXP and Liferay Portal
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
network
low complexity
liferay CWE-287
7.5
2021-05-13 CVE-2021-22155 Improper Authentication vulnerability in Blackberry Workspaces Server
An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account.
network
low complexity
blackberry CWE-287
8.8
2021-05-11 CVE-2020-26139 Improper Authentication vulnerability in multiple products
An issue was discovered in the kernel in NetBSD 7.1.
5.3
2021-05-10 CVE-2021-23008 Improper Authentication vulnerability in F5 Big-Ip Access Policy Manager
On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypassed via a spoofed AS-REP (Kerberos Authentication Service Response) response sent over a hijacked KDC (Kerberos Key Distribution Center) connection or from an AD server compromised by an attacker.
network
low complexity
f5 CWE-287
critical
9.8
2021-05-10 CVE-2021-31520 Improper Authentication vulnerability in Trendmicro IM Security 1.6/1.6.5
A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface.
network
high complexity
trendmicro CWE-287
8.1
2021-05-10 CVE-2021-26077 Improper Authentication vulnerability in Atlassian Connect Spring Boot
Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps.
network
low complexity
atlassian CWE-287
8.8
2021-05-06 CVE-2021-28152 Improper Authentication vulnerability in Hongdian H8922 Firmware 3.0.5
Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser.
network
low complexity
hongdian CWE-287
critical
9.8
2021-05-06 CVE-2021-32030 Improper Authentication vulnerability in Asus Gt-Ac2900 Firmware 3.0.0.4.386.41793
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface.
network
low complexity
asus CWE-287
critical
9.8