VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 26 of 167
  • CVE-2024-42462CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

  • CVE-2024-7503CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for…

  • CVE-2024-7007CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

  • CVE-2024-38437CriJul 21, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

  • CVE-2024-6422CriJul 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

  • CVE-2024-0949CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.

  • CVE-2024-36543CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists),…

  • CVE-2024-32735CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.07

    An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

  • CVE-2023-42121CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-39457CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-32764CriApr 26, 2024
    risk 0.64cvss 9.9epss 0.00

    A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-51478CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

  • CVE-2024-21014CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2024-3701CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

  • CVE-2024-3777CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

  • CVE-2023-1083CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.

  • CVE-2024-2921CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.

  • CVE-2023-5716CriJan 19, 2024
    risk 0.64cvss 9.8epss 0.01

    ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.

  • CVE-2023-49255CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user can execute commands in the context of…

  • CVE-2023-51987CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.