Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-11-16 CVE-2019-19562 Improper Authentication vulnerability in Harman Hermes 2.1
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
low complexity
harman CWE-287
4.6
2020-11-16 CVE-2019-19560 Improper Authentication vulnerability in Harman Hermes 1.5
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
low complexity
harman CWE-287
4.6
2020-11-13 CVE-2020-28638 Improper Authentication vulnerability in Dyne Tomb
ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.
network
low complexity
dyne CWE-287
critical
9.8
2020-11-12 CVE-2020-2050 Improper Authentication vulnerability in Paloaltonetworks Pan-Os
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate.
network
low complexity
paloaltonetworks CWE-287
8.2
2020-11-09 CVE-2020-26168 Improper Authentication vulnerability in Hazelcast and JET
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios.
network
low complexity
hazelcast CWE-287
critical
9.8
2020-11-09 CVE-2020-26542 Improper Authentication vulnerability in Percona Server 20201002
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.
network
low complexity
percona CWE-287
critical
9.8
2020-11-09 CVE-2020-23139 Improper Authentication vulnerability in Microweber 1.1.18
Microweber 1.1.18 is affected by broken authentication and session management.
local
low complexity
microweber CWE-287
5.5
2020-11-06 CVE-2020-25592 Improper Authentication vulnerability in multiple products
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens.
network
low complexity
saltstack debian CWE-287
critical
9.8
2020-11-05 CVE-2020-17510 Improper Authentication vulnerability in multiple products
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
network
low complexity
apache debian CWE-287
critical
9.8
2020-11-05 CVE-2020-8267 Improper Authentication vulnerability in UI Unifi Protect Firmware
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated messages without a valid token.This vulnerability was fixed in UniFi Protect v1.14.11 and newer.This issue does not impact UniFi Cloud Key Gen 2 plus.This issue does not impact UDM-Pro customers with UniFi Protect stopped.Affected Products:UDM-Pro firmware 1.7.2 and earlier.UNVR firmware 1.3.12 and earlier.Mitigation:Update UniFi Protect to v1.14.11 or newer version; the UniFi Protect controller can be updated through your UniFi OS settings.Alternatively, you can update UNVR and UDM-Pro to:- UNVR firmware to 1.3.15 or newer.- UDM-Pro firmware to 1.8.0 or newer.
network
low complexity
ui CWE-287
5.3