Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2023-03-10 CVE-2023-27532 Missing Authentication for Critical Function vulnerability in Veeam Backup & Replication
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.
network
low complexity
veeam CWE-306
7.5
2023-03-03 CVE-2022-45551 Missing Authentication for Critical Function vulnerability in ZBT We1626 Firmware 21.06.18
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.
network
low complexity
zbt CWE-306
critical
9.8
2023-02-28 CVE-2023-20857 Missing Authentication for Critical Function vulnerability in VMWare Workspace ONE Content 3.20/3.20.1/3.21
VMware Workspace ONE Content contains a passcode bypass vulnerability.
low complexity
vmware CWE-306
6.8
2023-02-20 CVE-2023-23452 Missing Authentication for Critical Function vulnerability in Sick Fx0-Gpnt00000 Firmware and Fx0-Gpnt00010 Firmware
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
network
low complexity
sick CWE-306
critical
9.8
2023-02-20 CVE-2023-23453 Missing Authentication for Critical Function vulnerability in Sick Fx0-Gent00000 Firmware and Fx0-Gent00010 Firmware
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
network
low complexity
sick CWE-306
critical
9.8
2023-02-20 CVE-2022-44216 Missing Authentication for Critical Function vulnerability in SIR Gnuboard 5.5.4/5.5.5
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions.
network
low complexity
sir CWE-306
7.5
2023-02-20 CVE-2023-25570 Missing Authentication for Critical Function vulnerability in Apolloconfig Apollo
Apollo is a configuration management system.
network
low complexity
apolloconfig CWE-306
7.5
2023-02-16 CVE-2022-47703 Missing Authentication for Critical Function vulnerability in Tianjie Cpe906-3 and Cpe906-3 Firmware
TIANJIE CPE906-3 is vulnerable to password disclosure.
network
low complexity
tianjie CWE-306
7.5
2023-02-16 CVE-2022-27891 Missing Authentication for Critical Function vulnerability in Palantir Gotham
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session.
network
low complexity
palantir CWE-306
5.3
2023-02-09 CVE-2022-48288 Missing Authentication for Critical Function vulnerability in Huawei Emui and Harmonyos
The bundle management module lacks authentication and control mechanisms in some APIs.
network
low complexity
huawei CWE-306
7.5