CWE-306
3,066 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,066)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Abb 2Gate E1 Firmware Gate E2 FirmwareNov 21, 2024 Jan 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, includin...Show more |
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster. |
1Epson 1Epson Workforce Wf 2861 Firmware Nov 21, 2024 Dec 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authenticatio...Show more |
1Rockwellautomation 161756 En2f Series A Firmware 1756 En2f Series B Firmware1756 En2f Series C Firmware+13 moreJun 3, 2026 Dec 7, 2018 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connecti...Show more |
1Philips 2Intellispace Pacs Isite PacsNov 21, 2024 Nov 19, 2018 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of...Show more |
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access. |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot. |
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by...Show more |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Oct 11, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424. |
3Debian StarwindsoftwareTinc Vpn3Debian Linux Starwind Virtual SanTincNov 21, 2024 Oct 10, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. |
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot. |
The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require an...Show more |
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack. |
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Sep 7, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601. |
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vuln...Show more |
The JMX/RMI interface in Nasdaq BWise 5.0 does not require authentication for an SAP BO Component, which allows remote attackers to execute arbitrary code via a session on port 81. |
1Martem 2Telem Gw6 Firmware Telem Gwm FirmwareNov 21, 2024 Jul 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process. |
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no...Show more |
1Calamp 3Lmu 3030 Cdma Firmware Lmu 3030 Gsm FirmwareLmu 3030 Obd Ii FirmwareNov 21, 2024 Jul 24, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / reseller. This interface must be password...Show more |
The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. The DBPower U818A WIFI quadcopter drone runs an FTP server that by defa...Show more |