CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,452 vulnerabilities with CWE-306
CVE-2019-25226 HIGH
Dongyoung Media DM-AP240T/W - Info Disclosure
CVE-2019-10941 MEDIUM
SINEMA Server < V14 SP3 - Unauthenticated System Configuration Backup File Access
CVSS 5.3
CVE-2019-25020 HIGH
Scytl sVote 2.1 - Unauthenticated Administrative Configuration Exposure via sdm-ws-rest API
CVSS 7.5
CVE-2019-11684 CRITICAL
Bosch VRM - Improper Access Control
CVSS 9.9
CVE-2019-16004 MEDIUM
Cisco Vision Dynamic Signage Director - Auth Bypass
CVSS 6.5
CVE-2019-5591 MEDIUM KEV
FortiOS < 6.2.0 - Unauthenticated Sensitive Information Interception via LDAP Server Impersonation
CVSS 6.5
CVE-2019-18666 CRITICAL
D-Link DAP-1360 Revision F Firmware < 6.12b01 - Unauthenticated Telnet Service Activation
CVSS 9.8
CVE-2019-5620 CRITICAL
MicroSCADA Pro SYS600 9.3 - Missing Authentication for Critical Function
CVSS 9.8
CVE-2019-19104 CRITICAL
ABB Telephone Gateway TG/S 3.2 - Info Disclosure
CVSS 9.1
CVE-2019-12524 CRITICAL
Squid < 4.7 - Unauthenticated Cache Manager Access via URL Encoding Bypass
CVSS 9.8
CVE-2019-16879 CRITICAL
HUSKY RTU 6049-E70 <5.0 - Auth Bypass
CVSS 9.8
CVE-2019-19092 LOW
Hitachi Energy eSOMS 4.0-6.0.3 - Viewstate Integrity Bypass via Missing Message Authentication Code
CVSS 3.5
CVE-2019-20624 MEDIUM
Samsung Android N(7.x) and O(8.x) - Unauthenticated Keyboard Learned Words Exposure via S-Voice Lock Screen
CVSS 5.3
CVE-2019-20598 LOW
Android - Unauthenticated Information Disclosure via Bixby Lock Screen
CVSS 2.4
CVE-2019-20595 LOW
Samsung Android P(9.0) - Unauthenticated Bluetooth Stack Toggle via Quick Panel
CVSS 2.4
CVE-2019-20579 LOW
Samsung Android N(7.x)-P(9.0) - Unauthenticated Location Information Sharing via Lock Screen
CVSS 2.4
CVE-2019-20559 LOW
Samsung Android P(9.0) - Unauthenticated Photo Access on Lock Screen
CVSS 2.4
CVE-2019-20550 MEDIUM
Samsung Android O(8.x) - Unauthenticated Access to Locked App Content via S Secure
CVSS 5.5
CVE-2019-20532 MEDIUM
Samsung Android O(8.x) P(9.0) Q(10.0) - Unauthenticated Developer Options Access
CVSS 5.3
CVE-2019-16258 MEDIUM
Homee Brain Cube V2 <2.23.0 - Privilege Escalation
CVSS 6.8
CVE-2019-15655 HIGH
D-Link DSL-2875AL Firmware < 1.00.05 - Unauthenticated Password Disclosure via /romfile.cfg Request
CVSS 7.5
CVE-2019-15654 HIGH
Comba AC2400 Firmware - Unauthenticated Password Disclosure via upcfgAction.php
CVSS 7.5
CVE-2019-12127 CRITICAL
ONAP OOM 3.0.0-4.0.0 - Unauthenticated Access to Services via Exposed Ports
CVSS 9.8
CVE-2019-12126 CRITICAL
ONAP DCAE 3.0.0-4.0.0 - Unauthenticated Full Service Access via Open Ports
CVSS 9.8
CVE-2019-12125 CRITICAL
ONAP 3.0.0-4.0.0 - Unauthenticated Access to ONAP Services via Exposed Ports
CVSS 9.8
Details
Vulnerabilities 2,452
Exploit Likelihood High