VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 22 of 149
  • CVE-2024-2921CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.

  • CVE-2023-5716CriJan 19, 2024
    risk 0.64cvss 9.8epss 0.01

    ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.

  • CVE-2023-49255CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of…

  • CVE-2023-51987CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.

  • CVE-2023-29485CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention module. NOTE: Heimdal…

  • CVE-2023-49693CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

  • CVE-2023-47674CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB,…

  • CVE-2023-34060CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the…

  • CVE-2023-41351CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log…

  • CVE-2023-22072CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle…

  • CVE-2023-22069CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-44116CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.

  • CVE-2023-4702CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

  • CVE-2023-37483CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.05

    SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.

  • CVE-2023-36669CriJul 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the…

  • CVE-2023-35830CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without…

  • CVE-2023-35854CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.06

    Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…

  • CVE-2023-31411CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

  • CVE-2023-27396CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following…

  • CVE-2023-30762CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions…