Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-08-21 CVE-2020-10123 Improper Authentication vulnerability in NCR Aptra XFS 04.02.01/05.01.00
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.
low complexity
ncr CWE-287
5.3
2020-08-21 CVE-2020-16239 Improper Authentication vulnerability in Philips Suresigns VS4 Firmware A.07.107
Philips SureSigns VS4, A.07.107 and prior.
network
low complexity
philips CWE-287
4.9
2020-08-20 CVE-2020-15149 Improper Authentication vulnerability in Nodebb
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server.
network
low complexity
nodebb CWE-287
critical
9.9
2020-08-17 CVE-2020-3411 Improper Authentication vulnerability in Cisco DNA Center
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system.
network
low complexity
cisco CWE-287
7.5
2020-08-17 CVE-2020-9233 Improper Authentication vulnerability in Huawei Fusioncompute 8.0.0
FusionCompute 8.0.0 have an insufficient authentication vulnerability.
network
low complexity
huawei CWE-287
critical
9.1
2020-08-14 CVE-2020-4662 Improper Authentication vulnerability in IBM Event Streams 10.0.0
IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation.
network
low complexity
ibm CWE-287
8.8
2020-08-13 CVE-2020-8685 Improper Authentication vulnerability in Intel LED Manager for NUC
Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-287
4.4
2020-08-13 CVE-2020-8714 Improper Authentication vulnerability in Intel products
Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-287
7.8
2020-08-13 CVE-2020-8713 Improper Authentication vulnerability in Intel products
Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-287
8.8
2020-08-13 CVE-2020-8709 Improper Authentication vulnerability in Intel products
Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-287
8.8