CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,337)
page 26 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42462 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9. | ||
| CVE-2024-7503 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for… | ||
| CVE-2024-7007 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2024 | Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application. | ||
| CVE-2024-38437 | Cri | 0.64 | 9.8 | 0.01 | Jul 21, 2024 | D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel | ||
| CVE-2024-6422 | Cri | 0.64 | 9.8 | 0.01 | Jul 10, 2024 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. | ||
| CVE-2024-0949 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68. | ||
| CVE-2024-36543 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2024 | Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists),… | ||
| CVE-2024-32735 | Cri | 0.64 | 9.8 | 0.07 | May 14, 2024 | An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application. | ||
| CVE-2023-42121 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2024 | Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw… | ||
| CVE-2023-39457 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2024 | Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. … | ||
| CVE-2024-32764 | Cri | 0.64 | 9.9 | 0.00 | Apr 26, 2024 | A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following… | ||
| CVE-2023-51478 | Cri | 0.64 | 9.8 | 0.01 | Apr 25, 2024 | Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19. | ||
| CVE-2024-21014 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2024 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network… | ||
| CVE-2024-3701 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services. | ||
| CVE-2024-3777 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password. | |
| CVE-2023-1083 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2024 | An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates. | |
| CVE-2024-2921 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions. | ||
| CVE-2023-5716 | Cri | 0.64 | 9.8 | 0.01 | Jan 19, 2024 | ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission. | ||
| CVE-2023-49255 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of… | ||
| CVE-2023-51987 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords. |
- risk 0.64cvss 9.8epss 0.01
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.
- risk 0.64cvss 9.8epss 0.01
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for…
- risk 0.64cvss 9.8epss 0.01
Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.
- risk 0.64cvss 9.8epss 0.01
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
- risk 0.64cvss 9.8epss 0.01
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists),…
- risk 0.64cvss 9.8epss 0.07
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.
- risk 0.64cvss 9.8epss 0.01
Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw…
- risk 0.64cvss 9.8epss 0.02
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. …
- risk 0.64cvss 9.9epss 0.00
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following…
- risk 0.64cvss 9.8epss 0.01
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- risk 0.64cvss 9.8epss 0.01
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network…
- risk 0.64cvss 9.8epss 0.01
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.
- risk 0.64cvss 9.8epss 0.01
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
- risk 0.64cvss 9.8epss 0.01
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
- risk 0.64cvss 9.8epss 0.01
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.
- risk 0.64cvss 9.8epss 0.01
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of…
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.