VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 137 of 169
  • CVE-2020-5780MedSep 10, 2020
    risk 0.35cvss 5.3epss 0.02

    Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.

  • CVE-2020-20627MedAug 31, 2020
    risk 0.35cvss 5.3epss 0.02

    The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

  • CVE-2020-3461MedJul 31, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on a specific part of…

  • CVE-2020-3333MedJun 3, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an affected device. An…

  • CVE-2020-12117MedMay 1, 2020
    risk 0.35cvss 5.3epss 0.01

    Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800. NOTE: Moxa Service is an unauthenticated service that runs upon a first-time installation but can be disabled…

  • CVE-2020-8497MedMar 23, 2020
    risk 0.35cvss 5.3epss 0.05

    In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

  • CVE-2020-10079MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

  • CVE-2019-19799MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.06

    Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

  • CVE-2019-19800MedFeb 6, 2020
    risk 0.35cvss 5.3epss 0.04

    Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

  • CVE-2019-4551MedFeb 4, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.

  • CVE-2019-16003MedJan 26, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to download system log files from an affected device. The vulnerability is due to an issue in the authentication logic of the web-based management…

  • CVE-2019-20143MedJan 13, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.

  • CVE-2019-16271MedJan 6, 2020
    risk 0.35cvss 5.3epss 0.02

    DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication.

  • CVE-2018-20507MedDec 30, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

  • CVE-2019-12390MedDec 2, 2019
    risk 0.35cvss 5.3epss 0.01

    Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.

  • CVE-2019-17235MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.01

    includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

  • CVE-2019-5643MedNov 6, 2019
    risk 0.35cvss 5.3epss 0.01

    Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular…

  • CVE-2019-16907MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI.

  • CVE-2019-13525MedOct 25, 2019
    risk 0.35cvss 5.3epss 0.01

    In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.

  • CVE-2019-15282MedOct 16, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device. The vulnerability is due an issue in the authentication logic of the…