CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,337)
page 36 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6198 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2020 | SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check. | ||
| CVE-2020-5328 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2020 | Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur. | ||
| CVE-2020-8636 | Cri | 0.64 | 9.8 | 0.04 | Feb 6, 2020 | An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution . | ||
| CVE-2014-3449 | Cri | 0.64 | 9.8 | 0.03 | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability | ||
| CVE-2019-17146 | Cri | 0.64 | 9.8 | 0.10 | Jan 7, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default.… | ||
| CVE-2019-18572 | Cri | 0.64 | 9.8 | 0.02 | Dec 18, 2019 | The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated… | ||
| CVE-2019-18339 | Cri | 0.64 | 9.8 | 0.03 | Dec 12, 2019 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A… | ||
| CVE-2019-18284 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2019 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other… | ||
| CVE-2019-15932 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2019 | Intesync Solismed 3.3sp has Incorrect Access Control. | ||
| CVE-2019-12503 | Cri | 0.64 | 9.8 | 0.02 | Dec 2, 2019 | Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system… | ||
| CVE-2019-12392 | Cri | 0.64 | 9.8 | 0.02 | Dec 2, 2019 | Anviz access control devices allow remote attackers to issue commands without a password. | ||
| CVE-2019-18925 | Cri | 0.64 | 9.8 | 0.01 | Nov 12, 2019 | Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication. | ||
| CVE-2006-0062 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window. | ||
| CVE-2006-0061 | Cri | 0.64 | 9.8 | 0.02 | Nov 6, 2019 | xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session. | ||
| CVE-2019-13547 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication. | ||
| CVE-2019-18465 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2019 | In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL… | ||
| CVE-2019-15064 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2019 | HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication. | ||
| CVE-2019-15940 | Cri | 0.64 | 9.8 | 0.02 | Oct 1, 2019 | Victure PC530 devices allow unauthenticated TELNET access as root. | ||
| CVE-2019-15068 | Cri | 0.64 | 9.8 | 0.02 | Sep 25, 2019 | A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication. | ||
| CVE-2019-5504 | Cri | 0.64 | 9.8 | 0.02 | Sep 24, 2019 | ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions. |
- risk 0.64cvss 9.8epss 0.01
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.
- risk 0.64cvss 9.8epss 0.01
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
- risk 0.64cvss 9.8epss 0.03
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
- risk 0.64cvss 9.8epss 0.10
This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default.…
- risk 0.64cvss 9.8epss 0.02
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated…
- risk 0.64cvss 9.8epss 0.03
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A…
- risk 0.64cvss 9.8epss 0.02
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other…
- risk 0.64cvss 9.8epss 0.02
Intesync Solismed 3.3sp has Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.02
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system…
- risk 0.64cvss 9.8epss 0.02
Anviz access control devices allow remote attackers to issue commands without a password.
- risk 0.64cvss 9.8epss 0.01
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
- risk 0.64cvss 9.8epss 0.01
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
- risk 0.64cvss 9.8epss 0.02
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
- risk 0.64cvss 9.8epss 0.03
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
- risk 0.64cvss 9.8epss 0.01
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL…
- risk 0.64cvss 9.8epss 0.01
HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
- risk 0.64cvss 9.8epss 0.02
Victure PC530 devices allow unauthenticated TELNET access as root.
- risk 0.64cvss 9.8epss 0.02
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
- risk 0.64cvss 9.8epss 0.02
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.