VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 30 of 167
  • CVE-2022-35733CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.02

    Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute…

  • CVE-2022-34858CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.02

    Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

  • CVE-2022-2242CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).

  • CVE-2022-35865CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from…

  • CVE-2022-20861CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-20858CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-20857CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-2141CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.

  • CVE-2021-41418CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

  • CVE-2022-30230CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions.

  • CVE-2022-26833CriMay 25, 2022
    risk 0.64cvss 9.4epss 0.38

    An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to…

  • CVE-2022-28660CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

  • CVE-2022-1300CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.

  • CVE-2022-28719CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.05

    Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to…

  • CVE-2022-0992CriApr 19, 2022
    risk 0.64cvss 9.8epss 0.03

    The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA…

  • CVE-2021-44259CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to this device as a friend…

  • CVE-2022-25251CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a…

  • CVE-2022-25247CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.04

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full…

  • CVE-2021-46384CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated…

  • CVE-2021-36888CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.07

    Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.