CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,452 vulnerabilities with CWE-306
CVE-2019-12130
CRITICAL
ONAP 3.0.0-4.0.0 - Unauthenticated Access to ONAP Services via Exposed Ports
CVSS 9.8
CVE-2019-12129
CRITICAL
ONAP 3.0.0-4.0.0 - Unauthenticated Access to Services via Open Ports
CVSS 9.8
CVE-2019-12128
CRITICAL
ONAP SO < 4.0.0 - Unauthenticated Access to Services via Open Ports
CVSS 9.8
CVE-2019-20529
HIGH
Frappe 11-12 - Unauthenticated Sensitive Data Exposure via Prepared Report File Storage
CVSS 7.5
CVE-2019-12120
CRITICAL
ONAP VNFSDK 3.0.0-4.0.0 - Unauthenticated Remote Code Execution via Port 8000
CVSS 9.8
CVE-2019-12119
CRITICAL
ONAP SDC < 4.0.0 - Unauthenticated Remote Code Execution via Port 7000
CVSS 9.8
CVE-2019-12118
CRITICAL
ONAP SDC < 4.0.0 - Unauthenticated Remote Code Execution via Port 7001
CVSS 9.8
CVE-2019-12117
CRITICAL
ONAP SDC 3.0.0-4.0.0 - Unauthenticated Remote Code Execution via Port 4001
CVSS 9.8
CVE-2019-12116
CRITICAL
ONAP SDC < 4.0.0 - Unauthenticated Remote Code Execution via Port 6000
CVSS 9.8
CVE-2019-12115
CRITICAL
ONAP SDC Dublin - Unauthenticated Remote Code Execution via Port 4000
CVSS 9.8
CVE-2019-12114
CRITICAL
ONAP < 4.0.0 - Unauthenticated RCE via Holmes Engine Management Pod Port 9202
CVSS 9.8
CVE-2019-20105
MEDIUM
Atlassian Application Links < 5.4.20 - Missing Authentication
CVSS 4.9
CVE-2019-13194
HIGH
Brother Printers - Unauthenticated Sensitive Information Disclosure via Specific URL
CVSS 7.5
CVE-2019-13205
HIGH
Kyocera ECOSYS M5526cdw 2R7_2000.001.701 Sensitive Info Exposure via Config Files
CVSS 7.5
CVE-2019-19799
MEDIUM
ManageEngine Applications Manager < 14600 - Unauthenticated Information Disclosure via WieldFeedServlet
CVSS 5.3
CVE-2019-19226
HIGH
D-Link DSL-2680 Firmware EU_1.03 - Broken Access Control
CVSS 7.5
CVE-2019-19225
HIGH
D-Link DSL-2680 Firmware EU_1.03 - Broken Access Control
CVSS 7.5
CVE-2019-19224
HIGH
D-Link DSL-2680 Firmware EU_1.03 - Info Disclosure
CVSS 7.5
CVE-2019-19800
MEDIUM
Zoho ManageEngine Applications Manager 14 < 14520 - Unauthenticated OS File Name Disclosure via FailOverHelperServlet
CVSS 5.3
CVE-2019-4551
MEDIUM
IBM Security Directory Server 6.4.0 - Auth Bypass
CVSS 5.3
CVE-2019-16893
HIGH
TP-Link TP-SG105E V4 1.0.0 Build 20181120 - Unauthenticated Device Reboot via reboot.cgi
CVSS 7.5
CVE-2019-19143
MEDIUM
TP-LINK TL-WR849N 0.9.1 4.16 - Unauthenticated Firmware Replacement via cgi/softup POST Request
CVSS 6.1
CVE-2019-19822
HIGH
TOTOLINK A3002RU < 2.0.0 - Unauthenticated Sensitive Data Exposure via Configuration Retrieval
CVSS 7.5
CVE-2019-16003
MEDIUM
Cisco UCS Director - Info Disclosure
CVSS 5.3
CVE-2019-19142
HIGH
Intelbras WRN 240 Firmware - Unauthenticated Firmware Replacement via Firmware.cfg URI
CVSS 7.5
Details
Vulnerabilities
2,452
Exploit Likelihood
High