CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root...Show more |
1Coscale Agent Project 1Coscale Agent Jun 17, 2026 Dec 15, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a remote attacker to achieve root access wit...Show more |
1Siemens 1Logo! 8 Bm Firmware Jun 17, 2026 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authoriza...Show more |
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart....Show more |
1Schneider Electric 23140cpu65150 Firmware 140cpu65160 Firmware140noc77101 Firmware+20 moreJun 17, 2026 Dec 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notific...Show more |
Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software. |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 10.0 CRITICAL· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even...Show more |
An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authent...Show more |
An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain the configuration file, including hashed credential data. Successful e...Show more |
1Openclinic Project 1Openclinic Jun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Informat...Show more |
1Docker 1Crux Linux Docker Image Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achi...Show more |
1Vsolcn 2V1600d Mini Firmware V1600d4l FirmwareJun 17, 2026 Nov 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update script starts a telnetd -l /bin/sh process that does not require authentica...Show more |
1Sagemcom 1F@st 3486 Router Firmware Jun 17, 2026 Nov 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.c...Show more |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Securityonionsolutions 1Security Onion Jun 17, 2026 Nov 23, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/...Show more |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and...Show more |
1Cisco 1Iot Field Network Director Jun 17, 2026 Nov 18, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affect...Show more |
1Cisco 1Iot Field Network Director Jun 17, 2026 Nov 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected soft...Show more |
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integr...Show more |
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impa...Show more |