VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 45 of 150
  • CVE-2020-4670CriMay 17, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID:…

  • CVE-2020-36333CriMay 5, 2021
    risk 0.59cvss 9.1epss 0.04

    themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

  • CVE-2020-28899CriMar 16, 2021
    risk 0.59cvss 9.1epss 0.02

    The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password,…

  • CVE-2021-26705CriMar 5, 2021
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke…

  • CVE-2020-27285CriJan 6, 2021
    risk 0.59cvss 9.1epss 0.01

    The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

  • CVE-2020-29551CriDec 23, 2020
    risk 0.59cvss 9.1epss 0.03

    An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _internal/pc/vpro.php,…

  • CVE-2020-15243CriOct 8, 2020
    risk 0.59cvss 9.1epss 0.01

    Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x…

  • CVE-2020-12506CriSep 30, 2020
    risk 0.59cvss 9.1epss 0.01

    Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO…

  • CVE-2020-6294CriAug 12, 2020
    risk 0.59cvss 9.1epss 0.02

    Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.

  • CVE-2020-16167CriAug 7, 2020
    risk 0.59cvss 9.1epss 0.02

    Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video…

  • CVE-2020-7589CriJun 10, 2020
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project files from affected devices. The security vulnerability could be exploited by…

  • CVE-2019-19104CriApr 22, 2020
    risk 0.59cvss 9.1epss 0.01

    The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules. This issue…

  • CVE-2020-9278CriApr 20, 2020
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.

  • CVE-2019-5080CriDec 18, 2019
    risk 0.59cvss 9.1epss 0.02

    An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A single packet can cause a denial of service and weaken…

  • CVE-2019-5078CriDec 18, 2019
    risk 0.59cvss 9.1epss 0.02

    An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of…

  • CVE-2019-5077CriDec 18, 2019
    risk 0.59cvss 9.1epss 0.02

    An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial…

  • CVE-2019-4244CriDec 10, 2019
    risk 0.59cvss 9.1epss 0.02

    IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.

  • CVE-2019-17512CriOct 16, 2019
    risk 0.59cvss 9.1epss 0.02

    There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file via act=clear&logtype=sysact to log_clear.php, which could be used to erase attack traces.

  • CVE-2019-11496CriSep 10, 2019
    risk 0.59cvss 9.1epss 0.01

    In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with…

  • CVE-2019-10668CriSep 9, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to…