CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,435 vulnerabilities with CWE-306
CVE-2023-5376 HIGH
Korenix JetNet Series - Unauthenticated TFTP Access
CVSS 8.6
CVE-2023-5881 HIGH
Genie Aladdin Connect Garage Door Opener Firmware < 14.1.1 - Unauthenticated Critical Function Access via Web Interface
CVSS 8.2
CVE-2023-29485 CRITICAL
Heimdal Thor < 3.5.3 - Unauthenticated Arbitrary Code Execution via DarkLayer Guard Module
CVSS 9.8
CVE-2023-6595 HIGH
WhatsUp Gold <2023.1 - Info Disclosure
CVSS 7.5
CVE-2023-6368 MEDIUM
WhatsUp Gold <2023.1 - Info Disclosure
CVSS 5.9
CVE-2023-6718 CRITICAL
Repox - Unauthenticated User Creation and Modification via Crafted POST Request
CVSS 9.4
CVE-2023-50263 LOW
Nautobot 1.x-2.0.x < 1.6.7/2.0.6 - Unauthenticated Arbitrary File Download via FileProxy Endpoints
CVSS 3.7
CVE-2023-32460 HIGH
Dell PowerEdge BIOS < 1.6.6 - Unauthenticated Privilege Escalation
CVSS 8.8
CVE-2023-49693 CRITICAL
NETGEAR ProSAFE Network Management System < 1.7.0.34 - Unauthenticated Remote Code Execution via JDWP
CVSS 9.8
CVE-2023-29063 LOW
FACSChorus Workstation - Info Disclosure
CVSS 2.4
CVE-2023-29061 MEDIUM
FACSChorus Workstation - Info Disclosure
CVSS 5.2
CVE-2023-29060 MEDIUM
FACSChorus - Unprotected Data Exposure via USB Port Access
CVSS 5.4
CVE-2023-3104 MEDIUM
Unitree A1 Firmware - Lack of Authentication
CVSS 5.7
CVE-2023-42770 CRITICAL
Redlioncontrols St-ipm-6350 Firmware - Missing Authentication
CVSS 10.0
CVE-2023-47674 CRITICAL
First Corporation DVRs - Unauthenticated Configuration Rewrite and Information Disclosure
CVSS 9.8
CVE-2023-34060 CRITICAL
VMware Cloud Director Appliance <10.5 - Auth Bypass
CVSS 9.8
CVE-2023-46096 MEDIUM
SIMATIC PCS neo <V4.1 - Auth Bypass
CVSS 6.5
CVE-2023-45140 MEDIUM
ovh/the-bastion < 3.14.15 - Missing Authentication for SCP/SFTP via Group-Based JIT MFA Bypass
CVSS 4.8
CVE-2023-46819 MEDIUM
Apache OFBiz <18.12.09 - Info Disclosure
CVSS 5.3
CVE-2023-4699 CRITICAL
Mitsubishielectric Fx3u-32mt/es Firmware - Missing Authentication
CVSS 10.0
CVE-2023-46381 HIGH
LOYTEC Devices - Unauthenticated RCE
CVSS 8.2
CVE-2023-41351 CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - Auth Bypass
CVSS 9.8
CVE-2023-46249 CRITICAL
authentik <2023.8.4-2023.10.2 - Privilege Escalation
CVSS 9.6
CVE-2023-46978 HIGH
TOTOLINK X6000R V9.4.0cu.852_B20230719 - Privilege Escalation
CVSS 7.5
CVE-2023-46747 CRITICAL KEV
F5 BIG-IP 13.1.0-13.1.4 - Unauthenticated Remote Command Execution via Configuration Utility Bypass
CVSS 9.8
Details
Vulnerabilities 2,435
Exploit Likelihood High