VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 84 of 150
  • CVE-2022-39412HigOct 18, 2022
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2022-38817HigOct 3, 2022
    risk 0.49cvss 7.5epss 0.03

    Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

  • CVE-2022-35572HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID. This web page calls a show_sysinfo function which retrieves WPA passwords, SSIDs, MAC…

  • CVE-2022-36604HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request.

  • CVE-2022-36619HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.

  • CVE-2022-37680HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encoder) and bellow allows attckers to remotely reboot the device via a crafted POST request to the endpoint /ptipupgrade.cgi. Security…

  • CVE-2022-36521HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

  • CVE-2022-37062HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.03

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite…

  • CVE-2022-30313HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected…

  • CVE-2022-30276HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)…

  • CVE-2021-34538HigJul 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized…

  • CVE-2022-28771HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.

  • CVE-2022-33138HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3).…

  • CVE-2022-21952HigJun 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java…

  • CVE-2022-32157HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients…

  • CVE-2022-32557HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.

  • CVE-2021-42893HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.

  • CVE-2021-42891HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.

  • CVE-2021-42889HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.

  • CVE-2022-27169HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to…