VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 32 of 167
  • CVE-2019-11684CriFeb 26, 2021
    risk 0.64cvss 9.9epss 0.01

    Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified…

  • CVE-2021-1396CriFeb 24, 2021
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more…

  • CVE-2021-1393CriFeb 24, 2021
    risk 0.64cvss 9.8epss 0.02

    Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more…

  • CVE-2020-15798CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.05

    A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150…

  • CVE-2020-14245CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.01

    HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.

  • CVE-2020-29165CriFeb 3, 2021
    risk 0.64cvss 9.8epss 0.02

    PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.

  • CVE-2020-23448CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.02

    newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.

  • CVE-2020-4958CriJan 21, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.

  • CVE-2020-13931CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.04

    If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously…

  • CVE-2020-35197CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-35196CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access…

  • CVE-2020-35195CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-35192CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35191CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.05

    The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-35190CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-35186CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35184CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35189CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2020-35187CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank…

  • CVE-2020-35185CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.