Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-12-22 CVE-2020-24579 Improper Authentication vulnerability in Dlink Dsl2888A Firmware
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55.
low complexity
dlink CWE-287
8.8
2020-12-21 CVE-2020-27254 Improper Authentication vulnerability in Emerson products
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.
network
low complexity
emerson CWE-287
7.5
2020-12-17 CVE-2020-27199 Improper Authentication vulnerability in Magic Home PRO Project Magic Home PRO 1.5.1
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass.
network
low complexity
magic-home-pro-project CWE-287
7.5
2020-12-15 CVE-2020-4747 Improper Authentication vulnerability in IBM Connect:Direct
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods.
network
low complexity
ibm CWE-287
critical
9.8
2020-12-14 CVE-2020-0460 Improper Authentication vulnerability in Google Android 11.0
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error.
network
low complexity
google CWE-287
7.5
2020-12-14 CVE-2020-25183 Improper Authentication vulnerability in Medtronic Mycarelink Smart Model 25000 Firmware
Medtronic MyCareLink Smart 25000 all versions contain an authentication protocol vuln where the method used to auth between MCL Smart Patient Reader and MyCareLink Smart mobile app is vulnerable to bypass.
low complexity
medtronic CWE-287
8.8
2020-12-14 CVE-2020-29669 Improper Authentication vulnerability in Macally Wifisd2-2A82 Firmware 2.000.010
In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password.
network
low complexity
macally CWE-287
8.8
2020-12-12 CVE-2020-35208 Improper Authentication vulnerability in Logmein Lastpass 4.8.11.2403
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS.
high complexity
logmein CWE-287
5.7
2020-12-12 CVE-2020-35207 Improper Authentication vulnerability in Logmein Lastpass 4.8.11.2403
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS.
high complexity
logmein CWE-287
5.7
2020-12-12 CVE-2020-29563 Improper Authentication vulnerability in Westerndigital MY Cloud OS 5
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118.
network
low complexity
westerndigital CWE-287
critical
9.8