VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 83 of 150
  • CVE-2022-48300HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48299HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48289HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48288HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-43447HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.01

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.

  • CVE-2023-21856HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2023-21842HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2023-21837HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to…

  • CVE-2022-42277HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can…

  • CVE-2022-42276HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can…

  • CVE-2022-46463HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.06

    An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

  • CVE-2022-45423HigDec 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

  • CVE-2022-45498HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

  • CVE-2022-24190HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.01

    The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a…

  • CVE-2022-42982HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP…

  • CVE-2021-46852HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-41776HigOct 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the…

  • CVE-2022-41629HigOct 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify…

  • CVE-2022-38870HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.03

    Free5gc v3.2.1 is vulnerable to Information disclosure.

  • CVE-2020-23648HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.