CWE-306
3,066 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,066)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Mobility Services Engine Policy SuiteNov 21, 2024 Jul 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote attacker to directly connect to the OSGi interface. The vulnerability is...Show more |
1Cisco 2Mobility Services Engine Policy SuiteNov 21, 2024 Jul 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentica...Show more |
1Cisco 1Mobility Services Engine Nov 21, 2024 Jul 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridNov 21, 2024 Jul 16, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name. |
1Hughes 4Dw7000 Firmware Hn7000s FirmwareHn7000sm Firmware+1 moreNov 21, 2024 Jul 13, 2018 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or http://[ip]/cgi/reboot.b...Show more |
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute. |
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device. |
1Universal Robots 1Cb3.1 Firmware Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execute the code. This enables a remote attacker who has access to the ports...Show more |
1Thetrackr 1Trackr Bravo Firmware Nov 21, 2024 Jul 6, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been release...Show more |
1Thetrackr 1Trackr Bravo Firmware Nov 21, 2024 Jul 6, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-20...Show more |
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a...Show more |
1Schneider Electric 1Evlink Charging Station Firmware Jun 17, 2026 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users...Show more |
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legit...Show more |
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device. |
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This...Show more |
1Suse 2Suse Linux Enterprise Desktop Suse Linux Enterprise ServerNov 21, 2024 Jun 8, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implemen...Show more |
1Vgate 1Icar 2 Wi Fi Obd2 Firmware Nov 21, 2024 May 30, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to...Show more |
1Netapp 1Oncommand Unified Manager Jun 17, 2026 Apr 25, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NetApp OnCommand Unified Manager for Linux versions 7.2 though 7.3 ship with the Java Debug Wire Protocol (JDWP) enabled which allows unauthorized local attackers to execute arbitrary code. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. |