Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-03-04 CVE-2021-25343 Improper Authentication vulnerability in Samsung Members 2.4.81.13/2.4.85.11
Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.
local
low complexity
samsung CWE-287
3.3
2021-03-04 CVE-2021-25342 Improper Authentication vulnerability in Samsung Members 2.4.81.13/2.4.85.11
Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.
local
low complexity
samsung CWE-287
3.3
2021-03-04 CVE-2021-25341 Improper Authentication vulnerability in Samsung S Assistant
Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.
local
low complexity
samsung CWE-287
3.3
2021-03-02 CVE-2021-21513 Improper Authentication vulnerability in Dell Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2021-03-01 CVE-2021-27878 Improper Authentication vulnerability in Veritas Backup Exec
An issue was discovered in Veritas Backup Exec before 21.2.
network
low complexity
veritas CWE-287
8.8
2021-03-01 CVE-2021-27877 Improper Authentication vulnerability in Veritas Backup Exec
An issue was discovered in Veritas Backup Exec before 21.2.
network
low complexity
veritas CWE-287
critical
9.8
2021-03-01 CVE-2021-27876 Improper Authentication vulnerability in Veritas Backup Exec
An issue was discovered in Veritas Backup Exec before 21.2.
network
low complexity
veritas CWE-287
8.1
2021-03-01 CVE-2021-3332 Improper Authentication vulnerability in Wpserveur WPS Hide Login 1.6.1
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
network
low complexity
wpserveur CWE-287
5.3
2021-02-27 CVE-2021-25281 Improper Authentication vulnerability in multiple products
An issue was discovered in through SaltStack Salt before 3002.5.
network
low complexity
saltstack fedoraproject debian CWE-287
critical
9.8
2021-02-26 CVE-2020-26200 Improper Authentication vulnerability in Kaspersky Endpoint Security and Rescue Disk
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity.
low complexity
kaspersky CWE-287
6.8