Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-02-25 CVE-2015-5201 Missing Authentication for Critical Function vulnerability in Redhat products
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.
network
low complexity
redhat CWE-306
7.5
2020-02-21 CVE-2020-9330 Missing Authentication for Critical Function vulnerability in Xerox products
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address.
network
low complexity
xerox CWE-306
8.8
2020-02-21 CVE-2020-5326 Missing Authentication for Critical Function vulnerability in Dell products
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu.
low complexity
dell CWE-306
5.3
2020-02-12 CVE-2020-6186 Missing Authentication for Critical Function vulnerability in SAP Host Agent 7.21
SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host Agent, leading to Denial of Service.
network
low complexity
sap CWE-306
7.5
2020-02-07 CVE-2020-6769 Missing Authentication for Critical Function vulnerability in Bosch products
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway.
network
low complexity
bosch CWE-306
critical
9.1
2020-02-06 CVE-2020-8636 Missing Authentication for Critical Function vulnerability in Opservices Opmon 9.3.2
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
network
low complexity
opservices CWE-306
critical
9.8
2020-02-06 CVE-2020-7954 Missing Authentication for Critical Function vulnerability in Opservices Opmon 9.3.2
An issue was discovered in OpServices OpMon 9.3.2.
local
low complexity
opservices CWE-306
7.8
2020-02-06 CVE-2020-7953 Missing Authentication for Critical Function vulnerability in Opservices Opmon 9.3.2
An issue was discovered in OpServices OpMon 9.3.2.
network
low complexity
opservices CWE-306
7.5
2020-02-06 CVE-2019-19800 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Applications Manager 14.0
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
network
low complexity
zohocorp CWE-306
5.3
2020-02-04 CVE-2019-4551 Missing Authentication for Critical Function vulnerability in IBM Security Directory Server
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.
network
low complexity
ibm CWE-306
5.3