VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 81 of 169
  • CVE-2023-2827HigJun 13, 2023
    risk 0.51cvss 7.9epss 0.00

    SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the…

  • CVE-2022-29957HigJul 26, 2022
    risk 0.51cvss 7.8epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk…

  • CVE-2022-28809HigJul 17, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the…

  • CVE-2022-29934HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.00

    USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.

  • CVE-2021-33658HigMar 11, 2022
    risk 0.51cvss 7.8epss 0.00

    atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.

  • CVE-2022-24396HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.01

    The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged…

  • CVE-2020-27225HigMar 9, 2021
    risk 0.51cvss 7.8epss 0.00

    In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich…

  • CVE-2020-26192HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH may potentially exploit this vulnerability to read arbitrary data, tamper with system software or deny service…

  • CVE-2020-10537HigFeb 5, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP port 4848. No password is required to access it with the administrator account.

  • CVE-2021-22159HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing…

  • CVE-2020-27985HigNov 23, 2020
    risk 0.51cvss 7.8epss 0.01

    Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home//SecurityOnion/setup/so-setup.

  • CVE-2020-11579HigSep 3, 2020
    risk 0.51cvss 7.5epss 0.27

    An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA…

  • CVE-2020-13150HigJun 15, 2020
    risk 0.51cvss 7.8epss 0.00

    D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filtering rules become active.

  • CVE-2020-7479HigMar 23, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the…

  • CVE-2020-7954HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by default allows the execution of programs (e.g. nmap) without…

  • CVE-2019-5164HigDec 3, 2019
    risk 0.51cvss 7.8epss 0.01

    An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network…

  • CVE-2011-2187HigNov 27, 2019
    risk 0.51cvss 7.8epss 0.00

    xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.

  • CVE-2019-15511HigNov 21, 2019
    risk 0.51cvss 7.8epss 0.01

    An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy…

  • CVE-2019-10915HigJul 11, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper authentication. The vulnerability could be exploited by an…

  • CVE-2019-12174HigJul 8, 2019
    risk 0.51cvss 7.8epss 0.00

    hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method of the me_hide_vpnhelper.Helper class in the me.hide.vpnhelper macOS privilege helper tool. This method takes user-supplied input…