VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 64 of 169
  • CVE-2023-32460HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.00

    Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2023-45851HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  This issue allows an attacker to force the Android Client application to connect to a malicious MQTT broker, enabling it to send fake…

  • CVE-2023-45220HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature…

  • CVE-2023-41255HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug…

  • CVE-2023-22087HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2023-38186HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.01

    Windows Mobile Device Management Elevation of Privilege Vulnerability

  • CVE-2023-37265CriJul 17, 2023
    risk 0.57cvss 9.8epss 0.07

    CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This…

  • CVE-2023-22906HigJul 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.

  • CVE-2023-2834CriJun 30, 2023
    risk 0.57cvss 9.8epss 0.02

    The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated…

  • CVE-2020-36724CriJun 7, 2023
    risk 0.57cvss 9.8epss 0.02

    The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use of a loose comparison on the hash which allows an attacker…

  • CVE-2022-27645HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the…

  • CVE-2023-28326CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.01

    Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room

  • CVE-2023-27980HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens…

  • CVE-2022-44784HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the Axis 1.4 instance, embedded directly into the applications, as hinted by the WEB-INF/web.xml file leaked through Local File Inclusion. Among…

  • CVE-2022-41644HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.

  • CVE-2022-3327CriOct 20, 2022
    risk 0.57cvss 9.8epss 0.01

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

  • CVE-2021-26637HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.

  • CVE-2022-32251HigJun 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allow an attacker to change the permissions of any user and…

  • CVE-2020-27376HigApr 7, 2022
    risk 0.57cvss 8.8epss 0.01

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

  • CVE-2021-33008HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.