Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU module
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct
Even if the authentication fails for local service authentication, the requested command could still execute regardless
An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electer
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allow
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionali
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, wh
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privilege
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulne
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Att
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authe
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before ver
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmwar
A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vu
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticat
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a rem
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5.
It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technolo
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This
The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges
Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of AP
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain
STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.0
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers ca
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attacke
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbit
Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypa
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported versi
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BI
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote att
VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated a
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started