22108 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.
The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2016-8796 | 多款Huawei设备拒绝服务漏洞 — USG9520,USG9560,USG9580, USG9520 V300R001C01,USG9560 V300R001C01,USG9580 V300R001C01 | 7.5 | - | 2017-04-02 |
| CVE-2017-7392 | TigerVNC 安全漏洞 — n/a | 7.5 | - | 2017-04-01 |
| CVE-2017-7394 | TigerVNC 安全漏洞 — n/a | 7.5 | - | 2017-04-01 |
| CVE-2017-7396 | TigerVNC 安全漏洞 — n/a | 7.5 | - | 2017-04-01 |
| CVE-2017-7285 | MikroTik RouterBoard 安全漏洞 — n/a | 7.5 | - | 2017-03-29 |
| CVE-2016-9463 | Nextcloud Server和ownCloud Server 安全漏洞 — Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9CWE-303 | 9.8 | - | 2017-03-28 |
| CVE-2016-9469 | GitLab 安全漏洞 — GitLab Community Edition & GitLab Enterprise Edition 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1CWE-749 | 8.2 | - | 2017-03-28 |
| CVE-2017-5237 | Eview EV-07S GPS Tracker 安全漏洞 — EV-07S GPS Tracker | 9.1 | - | 2017-03-27 |
| CVE-2017-2643 | Moodle 安全漏洞 — Moodle 3.2.x | 5.3 | - | 2017-03-26 |
| CVE-2016-7797 | Pacemaker 安全漏洞 — n/a | 5.9 | - | 2017-03-24 |
| CVE-2017-7240 | Miele Professional PG 8528 PST10 路径遍历漏洞 — n/a | 7.5 | - | 2017-03-24 |
| CVE-2017-6517 | Microsoft Skype 安全漏洞 — n/a | 8.8 | - | 2017-03-23 |
| CVE-2016-7468 | F5 BIG-IP 安全漏洞 — F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, PEM, PSM, | 7.5 | - | 2017-03-23 |
| CVE-2017-3851 | Cisco IOx Cisco Application-hosting Framework 路径遍历漏洞 — Cisco Application-Hosting FrameworkCWE-22 | 7.5 | - | 2017-03-22 |
| CVE-2017-3853 | Cisco IOx Data-in-Motion 安全漏洞 — Cisco IOxCWE-119 | 9.8 | - | 2017-03-22 |
| CVE-2017-3856 | Cisco IOS XE Software 安全漏洞 — Cisco IOS XECWE-399 | 7.5 | - | 2017-03-22 |
| CVE-2017-3857 | Cisco IOS和IOS XE Software 安全漏洞 — Cisco IOS and IOS XECWE-399 | 7.5 | - | 2017-03-22 |
| CVE-2017-3859 | Cisco ASR 920 Series Aggregation Services Routers Zero Touch Provisioning 安全漏洞 — Cisco IOS XE Software for Cisco ASR 920 Series RoutersCWE-134 | 8.6 | - | 2017-03-22 |
| CVE-2017-3864 | Cisco IOS和IOS XE Software 资源管理错误漏洞 — Cisco IOS and IOS XECWE-399 | 8.6 | - | 2017-03-22 |
| CVE-2017-3849 | Cisco IOS和IOS XE Software 安全漏洞 — Cisco IOS and IOS XECWE-20 | 7.4 | - | 2017-03-21 |
| CVE-2017-3850 | Cisco IOS和IOS XE Software 安全漏洞 — Cisco IOS and IOS XECWE-20 | 5.9 | - | 2017-03-21 |
| CVE-2016-4926 | Juniper Networks Junos Space 安全漏洞 — n/a | 9.8 | - | 2017-03-20 |
| CVE-2017-3815 | Cisco TelePresence Software Release 安全漏洞 — Cisco TelePresence Server | 8.2 | - | 2017-03-17 |
| CVE-2017-3866 | Cisco Prime Service Catalog 跨站脚本漏洞 — Cisco Prime Service Catalog | 6.1 | - | 2017-03-17 |
| CVE-2017-3867 | Cisco Adaptive Security Appliances Software 安全漏洞 — Cisco Adaptive Security Appliance | 5.3 | - | 2017-03-17 |
| CVE-2017-3868 | Cisco UCS Director 跨站脚本漏洞 — Cisco UCS Director | 6.1 | - | 2017-03-17 |
| CVE-2017-3870 | Cisco Web Security Appliance AsyncOS Software 安全漏洞 — Cisco Web Security Appliance | 5.8 | - | 2017-03-17 |
| CVE-2017-3872 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications Manager | 6.1 | - | 2017-03-17 |
| CVE-2017-3875 | Cisco Nexus 7000 Series Switches 安全漏洞 — Cisco Nexus 7000 Series Switches | 5.3 | - | 2017-03-17 |
| CVE-2017-3877 | Cisco Unified Communications Manager 跨站请求伪造漏洞 — Cisco Unified Communications Manager | 6.5 | - | 2017-03-17 |
Vulnerabilities classified as access:pre-auth represent 22108 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.