← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
2Siclock Tc100 Firmware
Siclock Tc400 Firmware
Nov 21, 2024
Jul 3, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legit...Show more
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legitimate user downloads and executes the modified client from the affected device, then he/she could obtain code execution on the client system.Show less
1Siemens
2Siclock Tc100 Firmware
Siclock Tc400 Firmware
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device.
1Apache
1Cassandra
Jun 17, 2026
Jun 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This...Show more
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.Show less
1Suse
2Suse Linux Enterprise Desktop
Suse Linux Enterprise Server
Nov 21, 2024
Jun 8, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implemen...Show more
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).Show less
1Vgate
1Icar 2 Wi Fi Obd2 Firmware
Nov 21, 2024
May 30, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to...Show more
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to connect to the network without authentication.Show less
1Netapp
1Oncommand Unified Manager
Jun 17, 2026
Apr 25, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code.
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
1Buffalo
1Wzr 1750dhp2 Firmware
Nov 21, 2024
Apr 9, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
1Brilliantts
2Fuze Card Ble Firmware
Fuze Card Mcu Firmware
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentica...Show more
An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentication is needed, as demonstrated by gatttool.Show less
1Contec Touch
1Smart Home Firmware
Jun 17, 2026
Mar 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.
1Trendmicro
1Email Encryption Gateway
Jun 17, 2026
Mar 15, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameter...Show more
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters.Show less
1Buffalo
1Wxr 1900dhp2 Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
1Corega
1Cg Wgr 1200 Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.
2Fedoraproject
Sddm Project
2Fedora
Sddm
Nov 21, 2024
Mar 8, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
1Siemens
9Digsi 4
En100 Ethernet Module Dnp3 FirmwareEn100 Ethernet Module Iec 104 Firmware+6 more
Nov 21, 2024
Mar 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 v...Show more
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). The device engineering mechanism allows an unauthenticated remote user to upload a modified device configuration overwriting access authorization passwords.Show less
1Siemens
5En100 Ethernet Module Dnp3 Firmware
En100 Ethernet Module Iec 104 FirmwareEn100 Ethernet Module Iec 61850 Firmware+2 more
Nov 21, 2024
Mar 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions),...Show more
A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions < V1.22). The web interface (TCP/80) of affected devices allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.Show less
1Sap
1Netweaver System Landscape Directory
Nov 21, 2024
Mar 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
1Eq 3
1Homematic Central Control Unit Ccu2 Firmware
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices.
1Zyxel
1P 870h 51 Firmware
Nov 21, 2024
Feb 21, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The...Show more
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numerous exposed CGI endpoints. The vulnerability is caused by improper access controls that allow access to critical functions without authentication. An attacker can use this vulnerability to reboot affected devices, along with other actions. Was ZDI-CAN-4540.Show less