VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 23 of 149
  • CVE-2023-33553CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.

  • CVE-2020-36713CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new…

  • CVE-2023-30604CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit this vulnerability to access system configuration interface, resulting in performing arbitrary…

  • CVE-2023-2704CriMay 19, 2023
    risk 0.64cvss 9.8epss 0.02

    The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated…

  • CVE-2023-1096CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user.

  • CVE-2023-28697CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.

  • CVE-2023-2231CriApr 21, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit…

  • CVE-2023-23451CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.01

    The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial…

  • CVE-2023-29411CriApr 18, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.

  • CVE-2022-41331CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

  • CVE-2022-36983CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.05

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetSettings class. The issue results from the lack of…

  • CVE-2023-1140CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.

  • CVE-2023-24838CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution.

  • CVE-2023-27060CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.

  • CVE-2023-25589CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.

  • CVE-2022-45140CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

  • CVE-2022-45138CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full…

  • CVE-2023-23453CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2023-23452CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2022-42970CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7,…