CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,451 vulnerabilities with CWE-306
CVE-2020-20627 MEDIUM
GiveWP < 2.5.9 - Unauthenticated Settings Change via Admin Actions
CVSS 5.3
CVE-2020-15483 MEDIUM
Niscomed M1000 Multipara Patient Monitor Firmware - Unauthenticated Root Shell via UART Debug Port
CVSS 6.8
CVE-2020-9062 MEDIUM
Diebold Nixdorf ProCash 2100xe USB ATMs - Info Disclosure
CVSS 5.3
CVE-2020-10124 HIGH
NCR SelfServ ATMs APTRA XFS 05.01.00 - Code Injection
CVSS 7.1
CVE-2020-24051 CRITICAL
Moog EXO Series - Privilege Escalation
CVSS 9.8
CVE-2020-3448 MEDIUM
Cisco Cyber Vision Center Software - Auth Bypass
CVSS 5.8
CVE-2020-17475 HIGH
MEGVII Koala 2.9.1-c3s - Info Disclosure
CVSS 7.5
CVE-2020-12106 CRITICAL
VPNCrypt M10 2.6.5 - Unauthenticated Administrative Function Access via Web Portal
CVSS 9.8
CVE-2020-6309 HIGH
SAP NetWeaver AS JAVA - Unauthenticated Denial of Service via Web Service
CVSS 7.5
CVE-2020-6294 CRITICAL
SAP Business Objects Business Intelligence Platform <4.3 - Auth Bypass
CVSS 9.1
CVE-2020-16167 CRITICAL
Robotemi Launcher OS < 13146 - Missing Authentication
CVSS 9.1
CVE-2020-15136 MEDIUM
ectd <3.4.10, <3.3.23 - Info Disclosure
CVSS 6.5
CVE-2020-15127 HIGH
Contour < 1.7.0 - Unauthenticated Denial of Service via Envoy Shutdown Endpoint
CVSS 7.5
CVE-2020-3461 MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Unauthenticated Information Disclosure via Web Interface
CVSS 5.3
CVE-2020-3376 HIGH
Cisco Data Center Network Manager - Unauthenticated Authentication Bypass via Hosted URLs
CVSS 7.3
CVE-2020-2076 CRITICAL
SICK Package Analytics <= 04.0.0 - Unauthenticated Authentication Bypass via REST API
CVSS 9.8
CVE-2020-15391 CRITICAL
DevSpace < 4.14.0 - Unauthenticated Remote Code Execution via WebSocket Protocol
CVSS 9.8
CVE-2020-10921 CRITICAL
C-MORE HMI EA9 Firmware <6.52 - RCE
CVSS 9.8
CVE-2020-10920 CRITICAL
C-MORE HMI EA9 Firmware <6.52 - RCE
CVSS 9.8
CVE-2020-15894 HIGH
D-Link DIR-816L Firmware 2.x - Unauthenticated Sensitive Information Exposure via getcfg.php DEVICE.ACCOUNT
CVSS 7.5
CVE-2020-12028 HIGH
FactoryTalk View SE - Authenticated Remote Code Execution via Unrestricted Data Handler
CVSS 7.3
CVE-2020-10605 HIGH
Grundfos CIM 500 <6.16.00 - Info Disclosure
CVSS 7.5
CVE-2020-13405 HIGH
Microweber <1.1.20 - Info Disclosure
CVSS 7.5
CVE-2020-14501 CRITICAL
Advantech iView < 5.6 - Unauthenticated Information Disclosure and Account Deletion
CVSS 9.8
CVE-2020-5373 MEDIUM
Dell EMC OpenManage Integration for Microsoft System Center < 7.2.1 - Unauthenticated Information Disclosure
CVSS 6.5
Details
Vulnerabilities 2,451
Exploit Likelihood High