VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 20 of 149
  • CVE-2024-54983CriDec 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.

  • CVE-2024-50375CriNov 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated…

  • CVE-2024-47138CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

  • CVE-2024-38643CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following…

  • CVE-2024-21855CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.02

    A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

  • CVE-2024-40404CriNov 13, 2024
    risk 0.64cvss 9.8epss 0.00

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.

  • CVE-2024-50489CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.0.45.

  • CVE-2024-50487CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.

  • CVE-2024-50486CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.

  • CVE-2024-49604CriOct 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

  • CVE-2024-49328CriOct 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

  • CVE-2024-45274CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.02

    An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

  • CVE-2024-9984CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

  • CVE-2024-8943CriOct 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log…

  • CVE-2024-9289CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating…

  • CVE-2024-46293CriSep 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does…

  • CVE-2024-8456CriSep 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.

  • CVE-2024-8310CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.01

    OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

  • CVE-2024-6981CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.01

    OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

  • CVE-2024-8277CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly…