Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1097

1097 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-29881 Siemens SICAM 访问控制错误漏洞 — SICAM T 5.3 Medium2022-05-10
CVE-2022-29879 Siemens SICAM 访问控制错误漏洞 — SICAM T 4.3 Medium2022-05-10
CVE-2022-29877 Siemens SICAM 访问控制错误漏洞 — SICAM P850 8.2 -2022-05-10
CVE-2022-0424 Popup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses Disclosure — Popup by Supsystic 5.3 -2022-05-09
CVE-2022-1388 F5 BIG-IP 访问控制错误漏洞 — BIG-IP 9.8 Critical2022-05-05
CVE-2022-27495 F5 NGINX Service Mesh 访问控制错误漏洞 — NGINX Service Mesh 6.5 Medium2022-05-05
CVE-2022-1300 Missing authentication in TRUMPF products may result in corruption of data — TruTops Boost 9.8 Critical2022-05-02
CVE-2021-25094 Tatsu < 3.3.12 - Unauthenticated RCE — Tatsu 8.1 -2022-04-25
CVE-2022-0878 Novel attack against the Combined Charging System (CCS) in electric vehicles to remotely cause a denial of service — Combined Charging System 4.6 Medium2022-04-12
CVE-2022-24829 Missing authentication in Garden — garden 8.1 High2022-04-11
CVE-2021-33008 AVEVA System Platform Missing Authentication for Critical Function — AVEVA System Platform 8.8 High2022-04-04
CVE-2020-14479 ICSA-20-147-01 Inductive Automation Ignition (Update B) — Ignition 7 Gateway 5.3 Medium2022-04-01
CVE-2022-0922 ICSMA-22-088-01 Philips e-Alert — e-Alert 6.5 Medium2022-04-01
CVE-2021-3589 Foreman 访问控制错误漏洞 — Foreman Ansible 9.9 -2022-03-23
CVE-2022-25251 PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function — Axeda agent 9.8 Critical2022-03-16
CVE-2022-25250 PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function — Axeda agent 7.5 High2022-03-16
CVE-2022-25247 PTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical Function — Axeda agent 9.8 Critical2022-03-16
CVE-2022-24396 SAP Focused Run 安全漏洞 — SAP Focused Run (Simple Diagnostics Agent) 7.8 -2022-03-08
CVE-2022-25922 ICSA-22-063-01 Missing Authentication for Critical Function in Trailer Power Line Communications (PLC) J2497 — PLC4TRUCKS 6.1 Medium2022-03-07
CVE-2020-10640 ICSA-20-140-02 Emerson OpenEnterprise — OpenEnterprise SCADA Software 10.0 Critical2022-02-24
CVE-2021-22823 Schneider Electric Interactive Graphical SCADA System访问控制错误漏洞 — Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) 9.1 -2022-02-11
CVE-2021-22805 Schneider Electric IGSS 访问控制错误漏洞 — Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) 9.1 -2022-02-11
CVE-2022-22809 Schneider Electric spaceLYnk 访问控制错误漏洞 — spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior) 5.3 -2022-02-09
CVE-2021-34870 Netgear NETGEAR 访问控制错误漏洞 — XR1000 6.5 -2022-01-25
CVE-2021-23843 Lack of authentication mechanisms on the device — AMS 8.8 High2022-01-19
CVE-2022-21691 Improper Access Control in Onionshare — onionshare 4.3 Medium2022-01-18
CVE-2021-43832 Improper Access Control in spinnaker — spinnaker 10.0 Critical2022-01-04
CVE-2021-45232 security vulnerability on unauthorized access. — Apache APISIX Dashboard 9.8 -2021-12-27
CVE-2021-36780 Unauthorized data access from replicas through vulnerable instance manager pods — Longhorn 8.1 High2021-12-17
CVE-2021-36779 Host operations allowed in privileged Longhorn managed pods — Longhorn 9.6 Critical2021-12-17

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1097 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.