Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2019-20464 Improper Authentication vulnerability in Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 Firmware
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices.
network
low complexity
sannce CWE-287
7.5
2021-04-02 CVE-2021-29012 Improper Authentication vulnerability in Dmasoftlab DMA Radius Manager 4.4.0
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session.
network
low complexity
dmasoftlab CWE-287
critical
9.8
2021-04-01 CVE-2021-23923 Improper Authentication vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-287
8.1
2021-04-01 CVE-2021-21982 Improper Authentication vulnerability in VMWare Carbon Black Cloud Workload 1.0/1.0.1
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token.
network
low complexity
vmware CWE-287
critical
9.1
2021-03-29 CVE-2019-5317 Improper Authentication vulnerability in multiple products
A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below.
low complexity
arubanetworks siemens CWE-287
6.8
2021-03-26 CVE-2021-21403 Improper Authentication vulnerability in Kongchuanhujiao Project Kongchuanhujiao
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability.
network
low complexity
kongchuanhujiao-project CWE-287
critical
9.8
2021-03-26 CVE-2021-3153 Improper Authentication vulnerability in Hashicorp Terraform Enterprise 2020071
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled.
network
low complexity
hashicorp CWE-287
6.5
2021-03-25 CVE-2021-25368 Improper Authentication vulnerability in Samsung Cloud
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
network
low complexity
samsung CWE-287
7.5
2021-03-25 CVE-2021-22496 Improper Authentication vulnerability in Microfocus Access Manager
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3.
network
low complexity
microfocus CWE-287
7.5
2021-03-22 CVE-2021-26070 Improper Authentication vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource.
network
low complexity
atlassian CWE-287
7.2