CWE-306
3,068 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,068)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 12Atv Imc Drive Controller Firmware Modicon Lmc058 FirmwareModicon Lmc078 Firmware+9 moreJun 17, 2026 May 22, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is...Show more |
1Siemens 2Simatic Pcs 7 Simatic WinccJun 17, 2026 May 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions...Show more |
1Siemens 1Logo!8 Bm Firmware Jun 17, 2026 May 14, 2019 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp could perform device reconfigurations and obtain project files from the devices. Th...Show more |
Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users. This vulnerability can be exp...Show more |
1Lg 3Gamp 7100 Firmware Gapm 7200 FirmwareGapm 8000 FirmwareJun 17, 2026 May 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_d...Show more |
1Wincofireworks 1Fw 1007 Firmware Jun 17, 2026 May 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability. |
1Coship 4Rt3050 Firmware Rt3052 FirmwareRt7620 Firmware+1 moreJun 17, 2026 May 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wirel...Show more |
1Fujifilm 3Cr Ir 357 Fcr Capsula X Firmware Cr Ir 357 Fcr Carbon X FirmwareCr Ir 357 Fcr Xc 2 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who succ...Show more |
1Tibco 5Activematrix Bpm Activematrix Policy DirectorActivematrix Service Bus+2 moreJun 17, 2026 Apr 24, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TI...Show more |
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers to execute arbitrary c...Show more |
2Heketi Project Redhat2Heketi Openshift Container PlatformJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3....Show more |
An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary...Show more |
1Motorola 2Cx2 Firmware M2 FirmwareJun 17, 2026 Apr 18, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected clie...Show more |
A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the develop...Show more |
1Dasannetworks 1H660rm Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a...Show more |
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users. |
Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC. |
VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a J...Show more |
1Enttec 3Datagate Mk2 Firmware Pixelator FirmwareStorm 24 FirmwareJun 17, 2026 Mar 28, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to initiate a remote reboot, which may be used to cause a denial of service c...Show more |
1Dlink 5Dir 816 Firmware Dir 816l FirmwareDir 817lw Firmware+2 moreJun 17, 2026 Mar 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited t...Show more |