Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-07-14 CVE-2020-10044 Missing Authentication for Critical Function vulnerability in Siemens products
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18).
network
low complexity
siemens CWE-306
7.5
2020-07-14 CVE-2020-10038 Missing Authentication for Critical Function vulnerability in Siemens products
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18).
network
low complexity
siemens CWE-306
critical
9.8
2020-07-14 CVE-2020-6287 Missing Authentication for Critical Function vulnerability in SAP Netweaver Application Server Java
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
network
low complexity
sap CWE-306
critical
10.0
2020-07-03 CVE-2020-10282 Missing Authentication for Critical Function vulnerability in Dronecode Micro AIR Vehicle Link 1.0.0
The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attacks and more.
network
low complexity
dronecode CWE-306
critical
9.8
2020-07-02 CVE-2020-5910 Missing Authentication for Critical Function vulnerability in F5 Nginx Controller
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
network
low complexity
f5 CWE-306
7.5
2020-07-02 CVE-2020-3402 Missing Authentication for Critical Function vulnerability in Cisco Unified Customer Voice Portal
A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-306
7.5
2020-07-01 CVE-2020-13382 Missing Authentication for Critical Function vulnerability in Os4Ed Opensis
openSIS through 7.4 has Incorrect Access Control.
network
low complexity
os4ed CWE-306
critical
9.1
2020-06-26 CVE-2020-15336 Missing Authentication for Critical Function vulnerability in Zyxel Cloudcnm Secumanager 3.1.0/3.1.1
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
network
low complexity
zyxel CWE-306
7.5
2020-06-26 CVE-2020-15335 Missing Authentication for Critical Function vulnerability in Zyxel Cloudcnm Secumanager 3.1.0/3.1.1
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
network
low complexity
zyxel CWE-306
7.5
2020-06-24 CVE-2020-11961 Missing Authentication for Critical Function vulnerability in MI Xiaomi R3600 Firmware
Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication
network
low complexity
mi CWE-306
7.5