Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1096

1096 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2019-10915 Siemens TIA Administrator 访问控制错误漏洞 — TIA Administrator 7.8 -2019-07-11
CVE-2019-1876 Cisco Wide Area Application Services Software HTTPS Proxy Authentication Bypass Vulnerability — Cisco Wide Area Application Services (WAAS) 5.3 -2019-06-20
CVE-2019-1631 Cisco Integrated Management Controller Information Disclosure Vulnerability — Cisco Unified Computing System (Management Software) 5.3 -2019-06-20
CVE-2019-1629 Cisco Integrated Management Controller Arbitrary File Write Vulnerability — Cisco Unified Computing System (Management Software) 7.5 -2019-06-20
CVE-2017-15123 Red Hat CloudForms 访问控制错误漏洞 — CloudForms 7.5 -2019-06-12
CVE-2019-6820 多款Schneider Electric产品访问控制错误漏洞 — Modicon and PacDrive Controller, All versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2 8.2 -2019-05-22
CVE-2019-10919 Siemens LOGO!8 BM 访问控制错误漏洞 — LOGO! 8 BM (incl. SIPLUS variants) 9.8 -2019-05-14
CVE-2019-10922 Siemens SIMATIC WinCC和SIMATIC PCS 7 访问控制错误漏洞 — SIMATIC PCS 7 V8.0 and earlier 9.8 -2019-05-14
CVE-2019-6542 ENTTEC Datagate MK2 访问控制错误漏洞 — Datagate MK2 7.5 -2019-03-28
CVE-2019-3917 Nokia Alcatel Lucent I-240W-Q GPON ONT 访问控制错误漏洞 — Alcatel Lucent I-240W-Q GPON ONT 7.5 -2019-03-05
CVE-2018-19636 Local root exploit via inclusion of attacker controlled shell script — supportutils 7.8 -2019-03-05
CVE-2019-6543 AVEVA Group plc InduSoft Web Studio和InTouch Edge HMI 访问控制错误漏洞 — AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update 8.4 -2019-02-13
CVE-2019-6533 Kunbus PR100088 Modbus 安全漏洞 — PR100088 Modbus gateway 9.1 -2019-02-12
CVE-2018-0181 Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent Software Redis Server Unauthenticated Access Vulnerability — Cisco Policy Suite (CPS) Software 9.1 -2019-01-10
CVE-2018-18995 ABB GATE-E1和GATE-E2 安全漏洞 — ABB GATE-E1 and GATE-E2 9.8 -2019-01-03
CVE-2018-17924 多款Rockwell Automation产品安全漏洞 — Rockwell Automation 7.5 -2018-12-07
CVE-2018-5393 TP-Link EAP Controller versions 2.5.3 and earlier lack RMI authentication — EAP Controller 9.8 -2018-09-28
CVE-2018-14796 Tec4Data SmartCooler 安全漏洞 — SmartCooler 7.5 -2018-09-20
CVE-2018-10603 Martem GW6和GWM 授权问题漏洞 — TELEM GW6 9.8 -2018-07-31
CVE-2017-2637 Red Hat OpenStack 权限许可和访问控制问题漏洞 — rhosp-director 10.0 -2018-07-26
CVE-2017-3217 CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / reseller — LMU 3030 OBD-II 8.1 -2018-07-24
CVE-2018-0374 Cisco Policy Suite 安全漏洞 — Cisco Policy Suite unknown 9.1 -2018-07-18
CVE-2018-0376 Cisco Policy Suite 安全漏洞 — Cisco Policy Suite unknown 7.5 -2018-07-18
CVE-2018-0377 Cisco Policy Suite 安全漏洞 — Cisco Policy Suite unknown 9.1 -2018-07-18
CVE-2017-2638 infinispan 安全漏洞 — infinispan 8.2 -2018-07-16
CVE-2016-6544 iTrack Easy's getgps data can be modified without authentication — Easy 7.5 -2018-07-13
CVE-2016-6549 Zizai Tech Nut allows for unauthenticated Bluetooth pairing — Tech Nut 4.3 -2018-07-13
CVE-2016-9496 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication to access certain pages — HN7740S 6.5 -2018-07-13
CVE-2018-10635 Universal Robots Robot Controllers 安全漏洞 — Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 9.8 -2018-07-11
CVE-2016-6540 TrackR Bravo is missing authentication for the cloud service and allows querying or sending of GPS data from unauthenticated users — Bravo Mobile Application 8.1 -2018-07-06

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1096 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.