CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,453 vulnerabilities with CWE-306
CVE-2017-17747
MEDIUM
TP-Link TL-SG108E v1.0.0 - Unauthenticated Denial of Service via Device Logout Functionality
CVSS 6.5
CVE-2017-17746
MEDIUM
TP-Link TL-SG108E Firmware 1.0.0 - Missing Authentication for Critical Function via NAT Gateway IP
CVSS 6.8
CVE-2017-3184
CRITICAL
ACTi D, B, I, and E series cameras >=A1D-500-V6.11.31-AC - Unauthenticated Factory Reset via Direct URL Access
CVSS 9.8
CVE-2017-12155
MEDIUM
openstack-tripleo-heat-templates - Info Disclosure
CVSS 6.3
CVE-2017-16241
HIGH
AMAG Symmetry Door Edge Network Controllers - RCE
CVSS 7.5
CVE-2017-8156
MEDIUM
Huawei B2338-168 Firmware V100R001C00 - Unauthenticated Serial Port Access
CVSS 6.8
CVE-2017-8155
HIGH
Huawei B2338-168 Firmware V100R001C00 - Unauthenticated Remote Command Execution via Specific Port
CVSS 8.4
CVE-2017-2708
MEDIUM
Huawei Nice Firmware < Nice-AL00C00B0135 - Unauthenticated Authentication Bypass via Find Phone Function
CVSS 4.6
CVE-2017-1523
HIGH
IBM InfoSphere Master Data Management Collaborative Edition 11.5 - Unauthenticated Report Download
CVSS 7.5
CVE-2017-10271
HIGH
KEV
Oracle WebLogic wls-wsat Component Deserialization RCE
CVSS 7.5
CVE-2017-5637
HIGH
Apache ZooKeeper 3.4.0-3.4.9 and 3.5.0-3.5.2 - Unauthenticated Denial of Service via wchp/wchc Commands
CVSS 7.5
CVE-2017-12822
CRITICAL
Sentinel LDK RTE < 7.55 - Unauthenticated Admin Interface Enabling and Disabling
CVSS 9.9
CVE-2017-13997
CRITICAL
Schneider Electric InduSoft Web Studio <8.0 SP2 - Auth Bypass
CVSS 9.8
CVE-2017-14350
CRITICAL
HPE Application Performance Management <9.40 - RCE
CVSS 9.8
CVE-2017-1483
HIGH
IBM Security Identity Manager 6.0-7.0 - Unauthenticated Critical Function Access
CVSS 8.6
CVE-2017-14417
CRITICAL
D-Link DIR-850L <FW208WWb02 - Info Disclosure
CVSS 9.8
CVE-2017-12733
CRITICAL
OPW SiteSentinel Integra 100/500 and iSite ATG Firmware < V175 - Unauthenticated Privilege Escalation
CVSS 9.8
CVE-2017-12440
HIGH
OpenStack Aodh < 6.0.1 - Authenticated Trust ID Spoofing via Alarm Action Scheme
CVSS 7.5
CVE-2017-6873
HIGH
Siemens OZW672/OZW772 - Info Disclosure
CVSS 7.4
CVE-2017-6872
MEDIUM
Siemens OZW672/OZW772 - Info Disclosure
CVSS 6.5
CVE-2017-4919
CRITICAL
VMware vCenter Server <6.5 - Privilege Escalation
CVSS 9.0
CVE-2017-4055
HIGH
McAfee Advanced Threat Defense 3.4-3.10 - Unauthenticated Detection Bypass via Web Interface
CVSS 7.5
CVE-2017-4052
CRITICAL
McAfee Advanced Threat Defense 3.4-3.10 - Authentication Bypass via HTTP Request
CVSS 9.8
CVE-2017-10804
CRITICAL
Odoo 8.0, 9.0, 10.0 - Unauthenticated Authentication Bypass via Null Byte Truncation
CVSS 9.8
CVE-2017-7315
CRITICAL
Humax Digital HG100R <2.0.6 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities
2,453
Exploit Likelihood
High