VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 31 of 150
  • CVE-2019-12120CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12119CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12118CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12117CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12116CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12115CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12114CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2020-6198CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.

  • CVE-2020-5328CriMar 6, 2020
    risk 0.64cvss 9.8epss 0.01

    Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.

  • CVE-2020-8636CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

  • CVE-2014-3449CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.03

    BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability

  • CVE-2019-17146CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.10

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default.…

  • CVE-2019-18572CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.02

    The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated…

  • CVE-2019-18339CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A…

  • CVE-2019-18284CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other…

  • CVE-2019-15932CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp has Incorrect Access Control.

  • CVE-2019-12503CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system…

  • CVE-2019-12392CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Anviz access control devices allow remote attackers to issue commands without a password.

  • CVE-2019-18925CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.01

    Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.

  • CVE-2006-0062CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.