VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 65 of 150
  • CVE-2023-26573HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

  • CVE-2023-22101HigOct 17, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-34392HigAug 31, 2023
    risk 0.53cvss 8.2epss 0.00

    A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A…

  • CVE-2023-36847MedKEVAug 17, 2023
    risk 0.53cvss 5.3epss 0.86

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't…

  • CVE-2023-2781HigJun 3, 2023
    risk 0.53cvss 8.1epss 0.01

    The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This…

  • CVE-2023-30744HigMay 9, 2023
    risk 0.53cvss 8.2epss 0.01

    In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further…

  • CVE-2022-34908HigFeb 27, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and…

  • CVE-2022-46145HigDec 2, 2022
    risk 0.53cvss 8.1epss 0.01

    authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows…

  • CVE-2022-1070HigOct 21, 2022
    risk 0.53cvss 8.2epss 0.01

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

  • CVE-2022-39426HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM…

  • CVE-2022-39425HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.02

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM…

  • CVE-2022-0993HigApr 19, 2022
    risk 0.53cvss 8.1epss 0.07

    The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects…

  • CVE-2021-36780HigDec 17, 2021
    risk 0.53cvss 8.1epss 0.00

    A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue…

  • CVE-2021-38147HigNov 29, 2021
    risk 0.53cvss 7.5epss 0.53

    Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel,…

  • CVE-2021-27395HigOct 12, 2021
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Process Historian 2020 (All versions). An interface in the…

  • CVE-2021-35979HigOct 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.

  • CVE-2021-27963HigMar 5, 2021
    risk 0.53cvss 8.2epss 0.02

    SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a POST request to /User/saveUser without any authentication or session header.

  • CVE-2021-20198HigFeb 23, 2021
    risk 0.53cvss 8.1epss 0.02

    A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker…

  • CVE-2020-26649HigOct 22, 2020
    risk 0.53cvss 8.1epss 0.01

    AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php

  • CVE-2020-12505HigSep 30, 2020
    risk 0.53cvss 8.2epss 0.01

    Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852, WAGO 750-880/xxx-xxx, WAGO 750-881, WAGO 750-831/xxx-xxx, WAGO 750-882, WAGO…