VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 25 of 149
  • CVE-2022-40202CriOct 31, 2022
    risk 0.64cvss 9.8epss 0.01

    The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function…

  • CVE-2022-2474CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized…

  • CVE-2022-22526CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.

  • CVE-2022-1368CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserver commands by monitoring web socket…

  • CVE-2022-35733CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute…

  • CVE-2022-34858CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

  • CVE-2022-2242CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).

  • CVE-2022-35865CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from…

  • CVE-2022-20861CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-20858CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-20857CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-2141CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.

  • CVE-2021-41418CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

  • CVE-2022-30230CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions.

  • CVE-2022-26833CriMay 25, 2022
    risk 0.64cvss 9.4epss 0.38

    An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to…

  • CVE-2022-28660CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

  • CVE-2022-1300CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.

  • CVE-2022-28719CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.04

    Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to…

  • CVE-2022-0992CriApr 19, 2022
    risk 0.64cvss 9.8epss 0.03

    The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA…

  • CVE-2021-44259CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to this device as a friend…