← Back
CWE-306

2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,579)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bkw
1Solar Log 500 Firmware
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker...Show more
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.Show less
1Wipro
1Holmes
Jun 17, 2026
Nov 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.
1Wipro
1Holmes
Jun 17, 2026
Nov 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to process...Show more
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.Show less
1Zohocorp
3Manageengine Servicedesk Plus
Manageengine Servicedesk Plus MspManageengine Supportcenter Plus
Jun 17, 2026
Nov 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servl...Show more
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.Show less
1Dlink
1Dwr 932c E1 Firmware
Jun 17, 2026
Nov 23, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to execute administrative actions.
1Apache
1Ozone
Jun 17, 2026
Nov 19, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.
1Min
1Minio Console
Jun 17, 2026
Nov 15, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when a...Show more
Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. All users on release v0.12.2 and before are affected and are advised to update to 0.12.3 or newer. Users unable to upgrade should add automountServiceAccountToken: false to the operator-console deployment in Kubernetes so no service account token will get mounted inside the pod, then disable the external identity provider authentication by unset the CONSOLE_IDP_URL, CONSOLE_IDP_CLIENT_ID, CONSOLE_IDP_SECRET and CONSOLE_IDP_CALLBACK environment variable and instead use the Kubernetes service account token.Show less
1Zohocorp
1Manageengine Log360
Jun 17, 2026
Nov 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to c...Show more
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An attacker can leverage this vulnerability to achieve remote code execution by replacing files executed by Log360 on startup.Show less
1D Link
1Dir 868lw Firmware
Jul 9, 2026
Oct 31, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
1Freeswitch
1Freeswitch
Jun 17, 2026
Oct 26, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. By default, SIP requests of the type...Show more
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. By default, SIP requests of the type SUBSCRIBE are not authenticated in the affected versions of FreeSWITCH. Abuse of this security issue allows attackers to subscribe to user agent event notifications without the need to authenticate. This abuse poses privacy concerns and might lead to social engineering or similar attacks. For example, attackers may be able to monitor the status of target SIP extensions. Although this issue was fixed in version v1.10.6, installations upgraded to the fixed version of FreeSWITCH from an older version, may still be vulnerable if the configuration is not updated accordingly. Software upgrades do not update the configuration by default. SIP SUBSCRIBE messages should be authenticated by default so that FreeSWITCH administrators do not need to explicitly set the `auth-subscriptions` parameter. When following such a recommendation, a new parameter can be introduced to explicitly disable authentication.Show less
1Freeswitch
1Freeswitch
Jun 17, 2026
Oct 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH d...Show more
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing. By default, SIP requests of the type MESSAGE (RFC 3428) are not authenticated in the affected versions of FreeSWITCH. MESSAGE requests are relayed to SIP user agents registered with the FreeSWITCH server without requiring any authentication. Although this behaviour can be changed by setting the `auth-messages` parameter to `true`, it is not the default setting. Abuse of this security issue allows attackers to send SIP MESSAGE messages to any SIP user agent that is registered with the server without requiring authentication. Additionally, since no authentication is required, chat messages can be spoofed to appear to come from trusted entities. Therefore, abuse can lead to spam and enable social engineering, phishing and similar attacks. This issue is patched in version 1.10.7. Maintainers recommend that this SIP message type is authenticated by default so that FreeSWITCH administrators do not need to be explicitly set the `auth-messages` parameter. When following such a recommendation, a new parameter can be introduced to explicitly disable authentication.Show less
1Emerson
3Wireless 1410 Gateway Firmware
Wireless 1410d Gateway FirmwareWireless 1420 Gateway Firmware
Jun 17, 2026
Oct 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change.
1Auvesy
1Versiondog
Jun 17, 2026
Oct 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.
1Siemens
4Simatic Process Historian 2013
Simatic Process Historian 2014Simatic Process Historian 2019+1 more
Jun 17, 2026
Oct 12, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Proce...Show more
A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Process Historian 2020 (All versions). An interface in the software that is used for critical functionalities lacks authentication, which could allow a malicious user to maliciously insert, modify or delete data.Show less
1Tad Uploader Project
1Tad Uploader
Jun 17, 2026
Oct 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
1Tadtools Project
1Tadtools
Jun 17, 2026
Oct 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
1Tad Book3 Project
1Tad Book3
Jun 17, 2026
Oct 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
1Tad Web Project
1Tad Web
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system.
1Digi
186350 Sr Firmware
Cm FirmwareConnect Es Firmware+15 more
Jun 17, 2026
Oct 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
1Bosch
12Indracontrol Xlc Firmware
Rexroth Indramotion Mlc L20 FirmwareRexroth Indramotion Mlc L25 Firmware+9 more
Jun 17, 2026
Oct 4, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are ex...Show more
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.Show less