VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 24 of 149
  • CVE-2023-0052CriJan 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an…

  • CVE-2020-23256CriJan 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electerms service.

  • CVE-2022-46732CriJan 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

  • CVE-2022-43976CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication.

  • CVE-2022-47377CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an…

  • CVE-2022-41272CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to…

  • CVE-2022-45481CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45479CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45477CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-46414CriDec 4, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.

  • CVE-2022-44001CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.

  • CVE-2022-44000CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

  • CVE-2022-43999CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

  • CVE-2022-42785CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.

  • CVE-2022-45378CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…

  • CVE-2022-27586CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase…

  • CVE-2022-27585CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads…

  • CVE-2022-27584CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the…

  • CVE-2022-27582CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on…

  • CVE-2022-41688CriOct 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user…