Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands”
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper au
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that c
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain
Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain acce
Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an
Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged r
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an atta
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker,
An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system com
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is pos
An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticate
Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any pre
PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any
The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute ar
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivilege
An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the we
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.
A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Pl
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or
A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service o
JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on p
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command a
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthent
An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to a
Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote un
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authent
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices.
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requi
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentica
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that chan
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of service
Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headles
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitiv
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started