Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2019-05-31 CVE-2019-9105 Missing Authentication for Critical Function vulnerability in Saet Tebe Small Firmware and Webapp
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call.
network
low complexity
saet CWE-306
7.5
2019-05-31 CVE-2019-10046 Missing Authentication for Critical Function vulnerability in Pydio 8.2.2
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.
network
low complexity
pydio CWE-306
5.3
2019-05-31 CVE-2019-9871 Missing Authentication for Critical Function vulnerability in Jector Fm-K75 Firmware
Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.
network
low complexity
jector CWE-306
critical
9.8
2019-05-31 CVE-2019-12500 Missing Authentication for Critical Function vulnerability in MI M365 Firmware
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands.
low complexity
mi CWE-306
6.5
2019-05-29 CVE-2019-6958 Missing Authentication for Critical Function vulnerability in Bosch products
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK).
network
low complexity
bosch CWE-306
critical
9.1
2019-05-23 CVE-2019-12289 Missing Authentication for Critical Function vulnerability in Vstracam C38S Firmware and C7824Wip Firmware
An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices.
network
low complexity
vstracam CWE-306
critical
9.8
2019-05-23 CVE-2019-12288 Missing Authentication for Critical Function vulnerability in multiple products
An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices.
network
low complexity
vstarcam vstracm CWE-306
critical
9.8
2019-05-22 CVE-2019-6808 Missing Authentication for Critical Function vulnerability in Schneider-Electric products
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
network
low complexity
schneider-electric CWE-306
critical
9.8
2019-05-22 CVE-2019-6820 Missing Authentication for Critical Function vulnerability in Schneider-Electric products
A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2
network
low complexity
schneider-electric CWE-306
8.2
2019-05-13 CVE-2019-9727 Missing Authentication for Critical Function vulnerability in Eq-3 Ccu3 Firmware
Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users.
network
low complexity
eq-3 CWE-306
7.5