When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,372 vulnerabilities with CWE-287
CVE-2014-2955
Raritan PX < 1.5.11 - Unauthenticated Authentication Bypass via Cipher Suite 0
CVE-2014-3312
Cisco Small Business SPA300 and SPA500 IP Phones - Unauthenticated Debug Console Access
CVE-2014-2614
HP SiteScope 11.1x-11.13 and 11.2x-11.24 - Authentication Bypass
CVE-2014-4168
iodine < 0.7.0 - Authentication Bypass via Error Handling
CVE-2014-4668
Cherokee <1.2.103 - Auth Bypass
CVE-2014-2005
MEDIUM
Sophos Disk Encryption <5.2.2 - Privilege Escalation
CVSS 6.8
CVE-2014-3053
IBM Security Access Manager for Web 8.0 Firmware 8.0.0.0-8.0.0.3 - Authentication Bypass via Local Management Interface
CVE-2014-2609
HP Executive Scorecard 9.40-9.41 - Unauthenticated Remote Code Execution via Java Glassfish Admin Console
CVE-2014-3295
Cisco NX-OS < 6.2(2a) - Unauthenticated Denial of Service via Malformed HSRP Packets
CVE-2014-3781
Dotclear < 2.6.3 - Unauthenticated Authentication Bypass via XML-RPC Empty Password
CVE-2014-3945
TYPO3 < 6.2 - Authentication Bypass via Password Hash Knowledge
CVE-2014-3944
TYPO3 6.2.0-6.2.2 - Improper Authentication
CVE-2014-3780
Citrix VDI-In-A-Box 5.3.x < 5.3.8 and 5.4.x < 5.4.4 - Authentication Bypass via Java Servlet
CVE-2014-3277
Cisco Unified Communications Domain Manager < 9.0(1) - Authenticated Information Disclosure via Crafted URL
CVE-2014-0214
Moodle <2.3.11-2.6.3 - Info Disclosure
CVE-2014-2938
Hanvon FaceID < 1.007.110 - Unauthenticated API Command Execution
CVE-2014-0643
RSA NetWitness < 9.8.5.19 & Security Analytics 10.2-10.2.4/10.3.x < 10.3.2 - Auth Bypass via Kerberos PAM
CVE-2014-3430
Dovecot 1.1-2.2.12 - Denial of Service via Incomplete SSL/TLS Handshake
CVE-2014-1682
Zabbix <2.8.20rc1, <2.0.11rc1, <2.2.2rc1 - Auth Bypass
CVE-2014-0090
Foreman < 1.4.2 - Session Fixation via Session ID Cookie
CVE-2014-0056
OpenStack Neutron <2013.2.3 - Privilege Escalation
CVE-2014-2181
Cisco Adaptive Security Appliance Software - Authenticated Arbitrary File Read via Crafted HTTP URL
CVE-2014-3139
Unitrends Enterprise Backup 7.3.0 - Unauthenticated Authentication Bypass via SNMPD Auth Parameter
CVE-2014-0769
Festo CECX-X-C1/M1 CoDeSys/SoftMotion - Unauthenticated Config Mod & Log Deletion
CVE-2014-0760
Festo CECX-X-C1 and CECX-X-M1 Modular Controllers with CoDeSys - Improper Authentication via Undocumented FTP Access
Details
Vulnerabilities
4,372
Exploit Likelihood
High