CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Aveva 2Indusoft Web Studio Intouch Machine Edition 2014Jun 17, 2026 Feb 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could le...Show more |
1Kunbus 1Pr100088 Modbus Gateway Firmware Jun 17, 2026 Feb 12, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166). |
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, wi...Show more |
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefau...Show more |
1Estrongs 1Es File Explorer File Manager Jun 17, 2026 Jan 16, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port re...Show more |
1Cisco 1Policy Suite For Mobile Nov 21, 2024 Jan 11, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacke...Show more |
1Cisco 2Cisco Policy Suite Diameter Routing Agent Cisco Policy Suite For MobileNov 21, 2024 Jan 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for s...Show more |
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity. |
1Abb 2Gate E1 Firmware Gate E2 FirmwareNov 21, 2024 Jan 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, includin...Show more |
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster. |
1Epson 1Epson Workforce Wf 2861 Firmware Nov 21, 2024 Dec 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authenticatio...Show more |
1Rockwellautomation 161756 En2f Series A Firmware 1756 En2f Series B Firmware1756 En2f Series C Firmware+13 moreJun 3, 2026 Dec 7, 2018 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connecti...Show more |
1Philips 2Intellispace Pacs Isite PacsNov 21, 2024 Nov 19, 2018 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of...Show more |
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access. |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot. |
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by...Show more |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 11, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424. |
3Debian StarwindsoftwareTinc Vpn3Debian Linux Starwind Virtual SanTincNov 21, 2024 Oct 10, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. |
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot. |
The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require an...Show more |