When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2012-6451
CRITICAL
Lorex LNC116 and LNC104 Firmware < 030312 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2012-3824
HIGH
Campaign Enterprise < 11.0.551 - Unauthenticated Improper Authentication
CVSS 7.5
CVE-2012-2714
CRITICAL
Drupal BrowserID <7.x-1.3 - Auth Bypass
CVSS 9.8
CVE-2012-1258
MEDIUM
Scrutinizer NetFlow & sFlow Analyzer < 9.0.1.19899 - Unauthenticated Privilege Escalation via User Preferences CGI
CVSS 6.5
CVE-2012-3462
HIGH
SSSD 1.9.0 - Improper Authentication via HBAC Rule Bypass
CVSS 8.8
CVE-2012-6710
CRITICAL
eXtplorer < 2.1.2 - Unauthenticated Authentication Bypass via Empty Password Array
CVSS 9.8
CVE-2012-0803
CRITICAL
Apache CXF 2.4.5 and 2.5.1 - Unauthenticated Authentication Bypass via Empty UsernameToken
CVSS 9.8
CVE-2012-6452
Axway Secure Messenger < 6.5 Updated Release 7 - User Enumeration via Authentication Response Timing
CVE-2012-5032
Cisco IOS < 15.1(1)SY3 - Unauthenticated VPN Traffic Manipulation via Flex-VPN Load-Balancing
CVE-2012-4658
Cisco IOS < 15.1(1)SY3 - Denial of Service via HTTP Session Termination Issue
CVE-2012-5158
Puppet Enterprise <2.6.1 - Privilege Escalation
CVE-2012-1100
Red Hat JBoss Operations Network (JON) <3.0.1-2.4.2 - Auth Bypass
CVE-2012-0062
Red Hat JBoss Operations Network < 2.4.2 and 3.0.x < 3.0.1 - Unauthenticated Session Hijack via Agent Registration
CVE-2012-4078
Cisco Unified Computing System - Authentication Bypass via SSH Port Forwarding
CVE-2012-6603
PAN-OS < 3.1.12, 4.0.x < 4.0.10, 4.1.x < 4.1.4 - Unauthenticated Authentication Bypass
CVE-2012-4446
Apache Qpid < 0.20 - Unauthenticated Authentication Bypass via AMQP Federation Tag
CVE-2012-5633
Apache CXF <2.5.8, <2.6.5, <2.7.2 - Auth Bypass
CVE-2012-4066
Eucalyptus < 3.2.0 - Improper Authentication in Walrus Internal Message Protocol
CVE-2012-6274
BigAntSoft BigAnt IM Message Server - Unauthenticated Arbitrary File Write via File Upload
CVE-2012-5952
IBM WebSphere Message Broker 6.1-7.0 - Improper Authentication
CVE-2012-5940
IBM Netezza WebAdmin 6.0.5 6.0.8 7.0 - Unauthenticated Credential Exposure via Network Sniffing
CVE-2012-6354
IBM SAN Volume Controller and Storwize V7000 < 6.4.1.3 - Unauthenticated Authentication Bypass
CVE-2012-0874
JBoss EAP < 5.2.0 - Unauthenticated Remote Code Execution via JMX/EJB Invoker
CVE-2012-0702
IBM InfoSphere Information Server 8.1, 8.5-8.7 - Authenticated Privilege Escalation
CVE-2012-6440
MEDIUM
Rockwell Automation ControlLogix/CompactLogix - Improper Web Server Authentication
CVSS 4.8
Details
Vulnerabilities
4,374
Exploit Likelihood
High