Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-02-21 CVE-2020-5326 Missing Authentication for Critical Function vulnerability in Dell products
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu.
low complexity
dell CWE-306
5.3
2020-02-12 CVE-2020-6186 Missing Authentication for Critical Function vulnerability in SAP Host Agent 7.21
SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host Agent, leading to Denial of Service.
network
low complexity
sap CWE-306
7.5
2020-02-07 CVE-2020-6769 Missing Authentication for Critical Function vulnerability in Bosch products
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway.
network
low complexity
bosch CWE-306
critical
9.1
2020-02-06 CVE-2020-8636 Missing Authentication for Critical Function vulnerability in Opservices Opmon 9.3.2
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
network
low complexity
opservices CWE-306
critical
9.8
2020-02-06 CVE-2020-7954 Missing Authentication for Critical Function vulnerability in Opservices Opmon 9.3.2
An issue was discovered in OpServices OpMon 9.3.2.
local
low complexity
opservices CWE-306
7.8
2020-02-06 CVE-2020-7953 Missing Authentication for Critical Function vulnerability in Opservices Opmon 9.3.2
An issue was discovered in OpServices OpMon 9.3.2.
network
low complexity
opservices CWE-306
7.5
2020-02-06 CVE-2019-19800 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Applications Manager 14.0
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
network
low complexity
zohocorp CWE-306
5.3
2020-02-04 CVE-2019-4551 Missing Authentication for Critical Function vulnerability in IBM Security Directory Server
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.
network
low complexity
ibm CWE-306
5.3
2020-02-03 CVE-2019-16893 Missing Authentication for Critical Function vulnerability in Tp-Link Tp-Sg105E Firmware 1.0.0
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.
network
low complexity
tp-link CWE-306
7.5
2020-01-27 CVE-2019-19143 Missing Authentication for Critical Function vulnerability in Tp-Link Tl-Wr849N Firmware 0.9.14.16
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.
low complexity
tp-link CWE-306
6.1