When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2013-3430
Cisco Video Surveillance Manager < 7.0.0 - Unauthenticated Sensitive Information Exposure
CVE-2013-3656
Cybozu Office < 9.1.0 - Unauthenticated Authentication Bypass via Login URL
CVE-2013-4877
Verizon Wireless Network Extender - Info Disclosure
CVE-2013-4875
Verizon Wireless Network Extender SCS-2U01 - Privilege Escalation
CVE-2013-4874
Verizon Wireless Network Extender - Unauthenticated Root Access via HDMI Cable
CVE-2013-4784
HP Integrated Lights-Out BMC - Unauthenticated Authentication Bypass via Cipher Zero
CVE-2013-4783
Dell iDRAC6 <1.92 and iDRAC7 <1.23.23 - Auth Bypass
CVE-2013-4782
Supermicro BMC - Unauthenticated IPMI Command Execution via Cipher Zero
CVE-2013-3581
Choice Wireless WIXFMR-111 - Information Disclosure via Ajax wmxState or netState Request
CVE-2013-4731
Choice Wireless Green Packet WIXFMR-111 - RCE
CVE-2013-2310
SoftBank Wi-Fi Spot Configuration Software - Improper Authentication
CVE-2013-1205
Cisco WebEx Meetings Server - Info Disclosure
CVE-2013-0985
Mac OS X < 10.8.4 - Unauthenticated Denial of Service via FileVault Disable Command
CVE-2013-2067
Apache Tomcat 6.0.21-6.0.36 and 7.x < 7.0.33 - Session Fixation via Form Authentication
CVE-2013-2313
LOCKON EC-CUBE 2.11.0-2.12.3enP2 - Session Fixation
CVE-2013-1211
Cisco NX-OS - Improper Authentication via Spoofed STUN Packets or Crafted VMware ESXi Instance
CVE-2013-1209
Cisco NX-OS - Improper Authentication in VSM/VEM Communication
CVE-2013-2954
IBM InfoSphere Optim Data Growth - Auth Bypass
CVE-2013-2059
OpenStack Keystone Folsom <= 2012.2.4, Grizzly < 2013.1.1, Havana - Improper Authentication Token Revocation via v2 API
CVE-2013-1200
Cisco Secure ACS - Session Fixation
CVE-2013-1188
Cisco Unified Communications Manager - Denial of Service via Authentication Attempt Rate Limiting Bypass
CVE-2013-1337
Microsoft .NET Framework 4.5 - Authentication Bypass via WCF Endpoint
CVE-2013-0937
EMC Webtop <6.7 SP2 - Session Fixation
CVE-2013-0578
IBM Sterling Multi-Channel Fulfillment Solution & Selling and Fulfillment Foundation - Improper Authentication
CVE-2013-1241
Cisco IOS ISM Module - Denial of Service via Malformed Authentication-Header Packets
Details
Vulnerabilities
4,374
Exploit Likelihood
High