CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,453 vulnerabilities with CWE-306
CVE-2017-17747 MEDIUM
TP-Link TL-SG108E v1.0.0 - Unauthenticated Denial of Service via Device Logout Functionality
CVSS 6.5
CVE-2017-17746 MEDIUM
TP-Link TL-SG108E Firmware 1.0.0 - Missing Authentication for Critical Function via NAT Gateway IP
CVSS 6.8
CVE-2017-3184 CRITICAL
ACTi D, B, I, and E series cameras >=A1D-500-V6.11.31-AC - Unauthenticated Factory Reset via Direct URL Access
CVSS 9.8
CVE-2017-12155 MEDIUM
openstack-tripleo-heat-templates - Info Disclosure
CVSS 6.3
CVE-2017-16241 HIGH
AMAG Symmetry Door Edge Network Controllers - RCE
CVSS 7.5
CVE-2017-8156 MEDIUM
Huawei B2338-168 Firmware V100R001C00 - Unauthenticated Serial Port Access
CVSS 6.8
CVE-2017-8155 HIGH
Huawei B2338-168 Firmware V100R001C00 - Unauthenticated Remote Command Execution via Specific Port
CVSS 8.4
CVE-2017-2708 MEDIUM
Huawei Nice Firmware < Nice-AL00C00B0135 - Unauthenticated Authentication Bypass via Find Phone Function
CVSS 4.6
CVE-2017-1523 HIGH
IBM InfoSphere Master Data Management Collaborative Edition 11.5 - Unauthenticated Report Download
CVSS 7.5
CVE-2017-10271 HIGH KEV
Oracle WebLogic wls-wsat Component Deserialization RCE
CVSS 7.5
CVE-2017-5637 HIGH
Apache ZooKeeper 3.4.0-3.4.9 and 3.5.0-3.5.2 - Unauthenticated Denial of Service via wchp/wchc Commands
CVSS 7.5
CVE-2017-12822 CRITICAL
Sentinel LDK RTE < 7.55 - Unauthenticated Admin Interface Enabling and Disabling
CVSS 9.9
CVE-2017-13997 CRITICAL
Schneider Electric InduSoft Web Studio <8.0 SP2 - Auth Bypass
CVSS 9.8
CVE-2017-14350 CRITICAL
HPE Application Performance Management <9.40 - RCE
CVSS 9.8
CVE-2017-1483 HIGH
IBM Security Identity Manager 6.0-7.0 - Unauthenticated Critical Function Access
CVSS 8.6
CVE-2017-14417 CRITICAL
D-Link DIR-850L <FW208WWb02 - Info Disclosure
CVSS 9.8
CVE-2017-12733 CRITICAL
OPW SiteSentinel Integra 100/500 and iSite ATG Firmware < V175 - Unauthenticated Privilege Escalation
CVSS 9.8
CVE-2017-12440 HIGH
OpenStack Aodh < 6.0.1 - Authenticated Trust ID Spoofing via Alarm Action Scheme
CVSS 7.5
CVE-2017-6873 HIGH
Siemens OZW672/OZW772 - Info Disclosure
CVSS 7.4
CVE-2017-6872 MEDIUM
Siemens OZW672/OZW772 - Info Disclosure
CVSS 6.5
CVE-2017-4919 CRITICAL
VMware vCenter Server <6.5 - Privilege Escalation
CVSS 9.0
CVE-2017-4055 HIGH
McAfee Advanced Threat Defense 3.4-3.10 - Unauthenticated Detection Bypass via Web Interface
CVSS 7.5
CVE-2017-4052 CRITICAL
McAfee Advanced Threat Defense 3.4-3.10 - Authentication Bypass via HTTP Request
CVSS 9.8
CVE-2017-10804 CRITICAL
Odoo 8.0, 9.0, 10.0 - Unauthenticated Authentication Bypass via Null Byte Truncation
CVSS 9.8
CVE-2017-7315 CRITICAL
Humax Digital HG100R <2.0.6 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 2,453
Exploit Likelihood High