Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2017-06-13 CVE-2017-6693 Missing Authorization vulnerability in Cisco Elastic Services Controller 2.2(9.76)/2.3(1)
A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Directory Access.
local
low complexity
cisco CWE-862
5.5
2017-06-08 CVE-2017-6639 Missing Authorization vulnerability in Cisco Prime Data Center Network Manager 10.1.0/10.1(1)/10.1(2)
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system.
network
low complexity
cisco CWE-862
critical
9.8
2017-06-06 CVE-2017-8083 Missing Authorization vulnerability in Compulab Intense PC Firmware and Mintbox 2 Firmware
CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges.
local
low complexity
compulab CWE-862
6.7
2017-06-02 CVE-2017-0896 Missing Authorization vulnerability in Zulip Server
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.
network
low complexity
zulip CWE-862
6.5
2017-05-28 CVE-2017-9232 Missing Authorization vulnerability in Canonical Juju
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
network
low complexity
canonical CWE-862
critical
9.8
2017-05-26 CVE-2017-9036 Missing Authorization vulnerability in Trendmicro Serverprotect 3.0
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.
local
low complexity
trendmicro CWE-862
7.8
2017-05-22 CVE-2017-6635 Missing Authorization vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system.
network
low complexity
cisco CWE-862
6.5
2017-05-18 CVE-2017-6622 Missing Authorization vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges.
network
low complexity
cisco CWE-862
critical
9.8
2017-05-01 CVE-2017-6565 Missing Authorization vulnerability in Franklinfueling Ts-550 EVO Firmware 2.3.0.7332
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service.
network
low complexity
franklinfueling CWE-862
8.8
2017-05-01 CVE-2017-6564 Missing Authorization vulnerability in Franklinfueling Ts-550 EVO Firmware 2.3.0.7332
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory.
network
low complexity
franklinfueling CWE-862
6.5