VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 28 of 149
  • CVE-2020-35184CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35189CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35187CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-35185CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-28929CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.01

    Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.

  • CVE-2020-35469CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.02

    The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35468CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.02

    The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35193CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.02

    The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35467CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35466CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35464CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35463CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35462CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-25228CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected…

  • CVE-2020-7540CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause…

  • CVE-2020-29311CriDec 10, 2020
    risk 0.64cvss 9.8epss 0.06

    Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.

  • CVE-2020-29389CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.02

    The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password.

  • CVE-2020-29058CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN,…

  • CVE-2020-7561CriNov 19, 2020
    risk 0.64cvss 9.8epss 0.03

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an…

  • CVE-2020-3531CriNov 18, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authenticate REST API calls.…