VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 37 of 167
  • CVE-2019-15896CriSep 10, 2019
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account…

  • CVE-2019-15102CriSep 6, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected…

  • CVE-2019-15819CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.

  • CVE-2019-13405CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining…

  • CVE-2019-9585CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, resulting in the ability to read, set and deletion of Metadata.

  • CVE-2019-1895CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The…

  • CVE-2019-13983CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.01

    Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.

  • CVE-2019-12468CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.03

    An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

  • CVE-2019-10121CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.03

    eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via the user authentication dialogue, aka HMCCU-153. This leads to automatic login as admin.

  • CVE-2019-10119CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.02

    eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via an invalid login attempt to the RemoteApi account, aka HMCCU-154. This leads to automatic login as…

  • CVE-2019-13131CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.03

    Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

  • CVE-2019-12890CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.04

    RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.

  • CVE-2019-11523CriJun 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and…

  • CVE-2019-9871CriMay 31, 2019
    risk 0.64cvss 9.8epss 0.05

    Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.

  • CVE-2019-12289CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files…

  • CVE-2019-12288CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve…

  • CVE-2019-6808CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.08

    A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.

  • CVE-2019-10922CriMay 14, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions). An attacker with network access to affected…

  • CVE-2019-7564CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the…

  • CVE-2019-10950CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.04

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access…