VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 21 of 149
  • CVE-2024-7015CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2.

  • CVE-2024-8584CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.

  • CVE-2024-4428CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.

  • CVE-2024-36445CriAug 22, 2024
    risk 0.64cvss 9.8epss 0.01

    Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

  • CVE-2024-42462CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

  • CVE-2024-7503CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for…

  • CVE-2024-7007CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

  • CVE-2024-38437CriJul 21, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

  • CVE-2024-6422CriJul 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

  • CVE-2024-0949CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.

  • CVE-2024-36543CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists),…

  • CVE-2024-32735CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.07

    An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

  • CVE-2023-42121CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-39457CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-32764CriApr 26, 2024
    risk 0.64cvss 9.9epss 0.00

    A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-51478CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

  • CVE-2024-21014CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2024-3701CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

  • CVE-2024-3777CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

  • CVE-2023-1083CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.