CWE-306
3,066 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,066)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on...Show more |
1Amag 3En 1dbc Firmware En 2dbc FirmwareStd FirmwareMay 13, 2026 Dec 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door...Show more |
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit...Show more |
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on a certain port. After accessing the network between the indoor and outdoor units of the CPE, an...Show more |
The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by specia...Show more |
1Ibm 1Infosphere Master Data Management May 13, 2026 Oct 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892. |
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitab...Show more |
2Apache Debian2Debian Linux ZookeeperMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooK...Show more |
1Sentinel 1Sentinel Ldk Rte Firmware May 13, 2026 Oct 4, 2017 N/A· v4 9.9 CRITICAL· v3 7.5 HIGH· v2 Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors. |
1Schneider Electric 2Wonderware Indusoft Web Studio Wonderware IntouchMay 13, 2026 Oct 3, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability...Show more |
1Hp 1Application Performance Management May 13, 2026 Sep 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution. |
1Ibm 3Security Identity Governance And Intelligence Security Identity ManagerSecurity Privileged Identity ManagerMay 13, 2026 Sep 28, 2017 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621. |
register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintended enrollment in mydlink Cloud Services. |
1Opwglobal 3Sitesentinel Integra 100 Firmware Sitesentinel Integra 500 FirmwareSitesentinel Isite Atg FirmwareMay 13, 2026 Sep 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versi...Show more |
Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme t...Show more |
1Siemens 2Ozw672 Firmware Ozw772 FirmwareMay 13, 2026 Aug 8, 2017 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the...Show more |
1Siemens 2Ozw672 Firmware Ozw772 FirmwareMay 13, 2026 Aug 8, 2017 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device. |
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate. |
1Mcafee 1Advanced Threat Defense May 13, 2026 Jul 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enfor...Show more |
1Mcafee 1Advanced Threat Defense May 13, 2026 Jul 12, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings,...Show more |