CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legit...Show more |
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device. |
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This...Show more |
1Suse 2Suse Linux Enterprise Desktop Suse Linux Enterprise ServerNov 21, 2024 Jun 8, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implemen...Show more |
1Vgate 1Icar 2 Wi Fi Obd2 Firmware Nov 21, 2024 May 30, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to...Show more |
1Netapp 1Oncommand Unified Manager Jun 17, 2026 Apr 25, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. |
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors. |
1Brilliantts 2Fuze Card Ble Firmware Fuze Card Mcu FirmwareJun 17, 2026 Apr 4, 2018 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentica...Show more |
1Contec Touch 1Smart Home Firmware Jun 17, 2026 Mar 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors. |
1Trendmicro 1Email Encryption Gateway Jun 17, 2026 Mar 15, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameter...Show more |
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors. |
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors. |
2Fedoraproject Sddm Project2Fedora SddmNov 21, 2024 Mar 8, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. |
1Siemens 9Digsi 4 En100 Ethernet Module Dnp3 FirmwareEn100 Ethernet Module Iec 104 Firmware+6 moreNov 21, 2024 Mar 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 v...Show more |
1Siemens 5En100 Ethernet Module Dnp3 Firmware En100 Ethernet Module Iec 104 FirmwareEn100 Ethernet Module Iec 61850 Firmware+2 moreNov 21, 2024 Mar 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions),...Show more |
1Sap 1Netweaver System Landscape Directory Nov 21, 2024 Mar 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity. |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices. |
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The...Show more |