When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2012-2414
Asterisk Open Source <10.3.1 - Command Injection
CVE-2012-1799
Siemens Scalance S S602/S612/S613 V2 < 2.3.0.3 - Unauthenticated Brute-Force via Web Server
CVE-2012-1808
Koyo ECOM Ethernet Module - Unauthenticated Improper Authentication
CVE-2012-1806
Koyo ECOM Ethernet Module - Improper Authentication via Short Password Length
CVE-2012-1840
AjaXplorer 3.2.x < 3.2.5 and 4.0.x < 4.0.4 - Improper Authentication via Cookie Handling
CVE-2012-1838
LG-Nortel ELO GS24M Switch - Unauthenticated Authentication Bypass via Direct Configuration Page Access
CVE-2012-0400
EMC RSA enVision <4.1.4 - Auth Bypass
CVE-2012-1256
easyvista < 2010 - Authentication Bypass via SSO URL Parameter Manipulation
CVE-2012-0240
Advantech WebAccess < 7.0 - Unauthenticated Remote Code Execution via GbScriptAddUp.asp
CVE-2012-0239
Advantech WebAccess < 7.0 - Unauthenticated Administrative Password Change via uaddUpAdmin.asp
CVE-2012-0931
CRITICAL
Schneider Electric Modicon Quantum PLC - DoS/RCE
CVSS 9.8
CVE-2011-2054
MEDIUM
Cisco ASA 5500 Series - Improper Authentication via Blank LDAP Password Bypass
CVSS 4.3
CVE-2011-4338
HIGH
Shaman 1.0.9 - Privilege Escalation
CVSS 7.8
CVE-2011-4628
CRITICAL
TYPO3 < 4.3.12, 4.4.x < 4.4.9, 4.5.x < 4.5.4 - Authentication Bypass
CVSS 9.8
CVE-2011-4973
CRITICAL
mod_nss 1.0.8 - Authentication Bypass via Hardcoded Password
CVSS 9.8
CVE-2011-4068
CRITICAL
packetfence < 3.0.1 - Unauthenticated Authentication Bypass via Empty Password
CVSS 9.8
CVE-2011-4091
libnet6 <1.3.14 - Info Disclosure
CVE-2011-5253
thegr dl 0.3-0.9 - Unauthenticated Arbitrary User Login via Authorization Header
CVE-2011-4085
JBoss Enterprise Application Platform <5.1.2 - Auth Bypass
CVE-2011-5100
McAfee Firewall Reporter < 5.1.0.6 - Improper Authentication via Cookie Handling
CVE-2011-4590
Moodle 2.0.x < 2.0.6 and 2.1.x < 2.1.3 - Authenticated Access Restriction Bypass via Webservice Login
CVE-2011-0011
qemu < 0.11.0 - Unauthenticated VNC Authentication Bypass
CVE-2011-5090
grboard 1.8.6.5 - Unauthenticated Database Modification via Multiple Scripts
CVE-2011-3620
Apache Qpid 0.12 - Improper Authentication during Cluster Join
CVE-2011-4022
Cisco Intrusion Prevention System 7.0 and 7.1 - Denial of Service via Authentication Attempt Exhaustion
Details
Vulnerabilities
4,376
Exploit Likelihood
High