Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2017-12-31 CVE-2017-18001 Missing Authentication for Critical Function vulnerability in Trustwave Secure web Gateway 11.8.0.27
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.
network
low complexity
trustwave CWE-306
critical
10.0
2017-12-20 CVE-2017-17747 Missing Authentication for Critical Function vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
low complexity
tp-link CWE-306
2.7
2017-12-20 CVE-2017-17746 Missing Authentication for Critical Function vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials.
low complexity
tp-link CWE-306
7.7
2017-12-12 CVE-2017-12155 Missing Authentication for Critical Function vulnerability in Ceph
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable.
local
ceph CWE-306
3.3
2017-12-10 CVE-2017-16241 Missing Authentication for Critical Function vulnerability in Amag En-1Dbc Firmware, En-2Dbc Firmware and STD Firmware
Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door controller commands (e.g., lock, unlock, add ID card value) by sending unauthenticated requests to the affected devices via Serial over TCP/IP, as demonstrated by a Ud command.
network
low complexity
amag CWE-306
5.0
2017-11-22 CVE-2017-8156 Missing Authentication for Critical Function vulnerability in Huawei B2338-168 Firmware V100R001C00
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port.
local
low complexity
huawei CWE-306
7.2
2017-11-22 CVE-2017-8155 Missing Authentication for Critical Function vulnerability in Huawei B2338-168 Firmware V100R001C00
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on a certain port.
local
low complexity
huawei CWE-306
7.2
2017-11-22 CVE-2017-2708 Missing Authentication for Critical Function vulnerability in Huawei Nice Firmware
The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability.
local
low complexity
huawei CWE-306
4.9
2017-10-24 CVE-2017-1523 Missing Authentication for Critical Function vulnerability in IBM Infosphere Master Data Management 11.5
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication.
network
low complexity
ibm CWE-306
5.0
2017-10-10 CVE-2017-5637 Missing Authentication for Critical Function vulnerability in multiple products
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.
network
low complexity
apache debian CWE-306
7.5