← Back
CWE-306

3,066 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (3,066)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ceph
1Ceph
May 13, 2026
Dec 12, 2017
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on...Show more
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenStack as though the attacker were the OpenStack service, thus potentially reading or modifying data in an OpenStack Block Storage volume.Show less
1Amag
3En 1dbc Firmware
En 2dbc FirmwareStd Firmware
May 13, 2026
Dec 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door...Show more
Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door controller commands (e.g., lock, unlock, add ID card value) by sending unauthenticated requests to the affected devices via Serial over TCP/IP, as demonstrated by a Ud command.Show less
1Huawei
1B2338 168 Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit...Show more
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit and log in to the CPE without authentication. Successful exploit could allow the attacker to take control over the outdoor unit.Show less
1Huawei
1B2338 168 Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on a certain port. After accessing the network between the indoor and outdoor units of the CPE, an...Show more
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on a certain port. After accessing the network between the indoor and outdoor units of the CPE, an attacker can deliver commands to the specific port of the outdoor unit and execute them without authentication. Successful exploit could allow the attacker to take control over the outdoor unit.Show less
1Huawei
1Nice Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by specia...Show more
The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.Show less
1Ibm
1Infosphere Master Data Management
May 13, 2026
Oct 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.
1Oracle
1Weblogic Server
Aug 13, 2026
Oct 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitab...Show more
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).Show less
2Apache
Debian
2Debian Linux
Zookeeper
May 13, 2026
Oct 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooK...Show more
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.Show less
1Sentinel
1Sentinel Ldk Rte Firmware
May 13, 2026
Oct 4, 2017
N/A· v4
9.9 CRITICAL· v3
7.5 HIGH· v2
Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.
1Schneider Electric
2Wonderware Indusoft Web Studio
Wonderware Intouch
May 13, 2026
Oct 3, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability...Show more
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.Show less
1Hp
1Application Performance Management
May 13, 2026
Sep 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution.
1Ibm
3Security Identity Governance And Intelligence
Security Identity ManagerSecurity Privileged Identity Manager
May 13, 2026
Sep 28, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintended enrollment in mydlink Cloud Services.
1Opwglobal
3Sitesentinel Integra 100 Firmware
Sitesentinel Integra 500 FirmwareSitesentinel Isite Atg Firmware
May 13, 2026
Sep 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versi...Show more
A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. An attacker may create an application user account to gain administrative privileges.Show less
1Openstack
1Openstack
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme t...Show more
Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme trust+http, which allows remote authenticated users with knowledge of trust IDs where Aodh is the trustee to obtain a Keystone token and perform unspecified authenticated actions by adding an alarm action with the scheme trust+http, and providing a trust id where Aodh is the trustee.Show less
1Siemens
2Ozw672 Firmware
Ozw772 Firmware
May 13, 2026
Aug 8, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the...Show more
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.Show less
1Siemens
2Ozw672 Firmware
Ozw772 Firmware
May 13, 2026
Aug 8, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.
1Vmware
1Vcenter Server
May 13, 2026
Jul 28, 2017
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
1Mcafee
1Advanced Threat Defense
May 13, 2026
Jul 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enfor...Show more
Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enforcement of authentication and authorization.Show less
1Mcafee
1Advanced Threat Defense
May 13, 2026
Jul 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings,...Show more
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings, or gain administrator functionality via a crafted HTTP request parameter.Show less