VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 82 of 150
  • CVE-2023-4335HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

  • CVE-2023-4334HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

  • CVE-2023-39380HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

  • CVE-2023-38379HigJul 16, 2023
    risk 0.49cvss 7.5epss 0.01

    The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero…

  • CVE-2022-48496HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2022-48494HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2023-31196HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensitive information of the affected products. Affected products and versions are as follows: AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier,…

  • CVE-2023-33247HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the…

  • CVE-2023-31227HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality.

  • CVE-2023-0116HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-31594HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.01

    IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.

  • CVE-2023-23444HigMay 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated…

  • CVE-2023-23906HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to execute some critical functions without authentication, e.g., rebooting the product.

  • CVE-2023-31444HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.

  • CVE-2023-29413HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.

  • CVE-2023-21979HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to…

  • CVE-2023-27747HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.01

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive information such as configurations and recordings.

  • CVE-2020-14140HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.01

    When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the…

  • CVE-2022-47703HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.01

    TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, and Hardware Version CPF906-V5.0_LCD_20200513.

  • CVE-2023-22803HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an attacker to change the PLC's mode arbitrarily.