VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 33 of 150
  • CVE-2019-9871CriMay 31, 2019
    risk 0.64cvss 9.8epss 0.06

    Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.

  • CVE-2019-12289CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files…

  • CVE-2019-12288CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve…

  • CVE-2019-6808CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.08

    A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.

  • CVE-2019-10922CriMay 14, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions). An attacker with network access to affected…

  • CVE-2019-7564CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the…

  • CVE-2019-10950CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.04

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access…

  • CVE-2019-8993CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.03

    The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service…

  • CVE-2019-7727CriApr 23, 2019
    risk 0.64cvss 9.8epss 0.04

    In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol by using the JMX connector. The…

  • CVE-2019-3899CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

  • CVE-2019-10041CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.02

    The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.

  • CVE-2019-10040CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.03

    The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /goform/SystemCommand to execute a system command without authentication.

  • CVE-2019-10039CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.02

    The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setSysAdm to edit the web or system account without authentication.

  • CVE-2019-9201CriFeb 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

  • CVE-2019-9125CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.

  • CVE-2019-0261CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.04

    Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for…

  • CVE-2019-0246CriJan 8, 2019
    risk 0.64cvss 9.8epss 0.03

    SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

  • CVE-2018-18995CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.03

    Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers,…

  • CVE-2018-13114CriOct 22, 2018
    risk 0.64cvss 9.8epss 0.02

    Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by ssid:;ping 192.168.1.2 in the body of a SETSSID command.

  • CVE-2018-11247CriAug 15, 2018
    risk 0.64cvss 9.8epss 0.03

    The JMX/RMI interface in Nasdaq BWise 5.0 does not require authentication for an SAP BO Component, which allows remote attackers to execute arbitrary code via a session on port 81.