VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 103 of 169
  • CVE-2019-5163HigDec 3, 2019
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to…

  • CVE-2019-12389HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.

  • CVE-2019-18980HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.00

    On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use…

  • CVE-2019-17234HigNov 12, 2019
    risk 0.49cvss 7.5epss 0.03

    includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.

  • CVE-2019-18230HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.01

    Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.

  • CVE-2019-16906HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These…

  • CVE-2019-13549HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.01

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning…

  • CVE-2019-17511HigOct 14, 2019
    risk 0.49cvss 7.5epss 0.02

    There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network structure.

  • CVE-2019-17532HigOct 12, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because…

  • CVE-2019-17505HigOct 11, 2019
    risk 0.49cvss 7.5epss 0.02

    D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack.

  • CVE-2019-15018HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant.

  • CVE-2019-17232HigOct 7, 2019
    risk 0.49cvss 7.5epss 0.04

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

  • CVE-2019-15895HigSep 9, 2019
    risk 0.49cvss 7.5epss 0.02

    search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.

  • CVE-2019-13406HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.02

    A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.

  • CVE-2019-15506HigAug 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send properly formatted requests to the web application and download sensitive files and information.…

  • CVE-2019-14511HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

  • CVE-2019-12634HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The…

  • CVE-2019-1010136HigJul 19, 2019
    risk 0.49cvss 7.5epss 0.02

    ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users…

  • CVE-2019-13338HigJul 9, 2019
    risk 0.49cvss 7.5epss 0.02

    In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.

  • CVE-2019-11020HigJul 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.