VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,961)

page 122 of 149
  • CVE-2024-36457MedJul 15, 2024
    risk 0.34cvss epss 0.00

    The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.

  • CVE-2024-21846MedApr 18, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gateway, resulting in a denial-of-service scenario.

  • CVE-2024-3774MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.

  • CVE-2023-6949MedApr 2, 2024
    risk 0.34cvss 5.2epss 0.00

    A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any…

  • CVE-2024-21824MedMar 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative…

  • CVE-2024-26263MedFeb 15, 2024
    risk 0.34cvss 5.3epss 0.00

    EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.

  • CVE-2023-5253MedJan 15, 2024
    risk 0.34cvss 5.3epss 0.00

    A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the…

  • CVE-2023-51062MedJan 13, 2024
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.

  • CVE-2023-29061MedNov 28, 2023
    risk 0.34cvss 5.2epss 0.00

    There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can potentially exploit this vulnerability to access the BIOS configuration and modify the drive boot order and BIOS pre-boot authentication.

  • CVE-2023-27261MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.

  • CVE-2023-26579MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff information by unauthenticated attackers.

  • CVE-2023-41367MedSep 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances,…

  • CVE-2023-37373MedAug 8, 2023
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages. An unauthenticated remote attacker could write arbitrary files to the affected application's file system.

  • CVE-2023-2187MedJun 7, 2023
    risk 0.34cvss 5.3epss 0.01

    On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password…

  • CVE-2023-24527MedApr 11, 2023
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a…

  • CVE-2023-24526MedMar 14, 2023
    risk 0.34cvss 5.3epss 0.01

    SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an…

  • CVE-2022-27891MedFeb 16, 2023
    risk 0.34cvss 5.3epss 0.00

    Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances. It is highly recommended that customers upgrade…

  • CVE-2022-45190MedFeb 8, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.

  • CVE-2022-3188MedDec 21, 2022
    risk 0.34cvss 5.3epss 0.01

    Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users. …

  • CVE-2022-31701MedDec 14, 2022
    risk 0.34cvss 5.3epss 0.01

    VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.