CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,982)
page 85 of 150| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26303 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of… | ||
| CVE-2022-26043 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a… | ||
| CVE-2022-26026 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2022 | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this… | ||
| CVE-2022-24935 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | Lexmark products through 2022-02-10 have Incorrect Access Control. | ||
| CVE-2022-23345 | Hig | 0.49 | 7.5 | 0.02 | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control. | ||
| CVE-2022-26267 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. | ||
| CVE-2021-44262 | Hig | 0.49 | 7.5 | 0.02 | Mar 17, 2022 | A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device. | ||
| CVE-2021-44260 | Hig | 0.49 | 7.5 | 0.07 | Mar 17, 2022 | A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router. | ||
| CVE-2022-25250 | Hig | 0.49 | 7.5 | 0.02 | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote… | ||
| CVE-2022-25508 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2022 | An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. | ||
| CVE-2021-46371 | Hig | 0.49 | 7.5 | 0.04 | Feb 14, 2022 | antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information. | ||
| CVE-2021-34543 | Hig | 0.49 | 7.5 | 0.03 | Dec 7, 2021 | The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system… | ||
| CVE-2021-38283 | Hig | 0.49 | 7.5 | 0.02 | Nov 29, 2021 | Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI. | ||
| CVE-2021-37624 | Hig | 0.49 | 7.5 | 0.04 | Oct 25, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam… | ||
| CVE-2021-41975 | Hig | 0.49 | 7.5 | 0.01 | Oct 8, 2021 | TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in. | ||
| CVE-2021-22012 | Hig | 0.49 | 7.5 | 0.01 | Sep 23, 2021 | The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. | ||
| CVE-2020-21934 | Hig | 0.49 | 7.5 | 0.02 | Jul 21, 2021 | An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed. | ||
| CVE-2021-20474 | Hig | 0.49 | 7.5 | 0.00 | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. | ||
| CVE-2021-22322 | Hig | 0.49 | 7.5 | 0.01 | Jun 3, 2021 | There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality. | ||
| CVE-2021-31793 | Hig | 0.49 | 7.5 | 0.01 | May 6, 2021 | An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take a snapshot from the… |
- risk 0.49cvss 7.5epss 0.01
An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of…
- risk 0.49cvss 7.5epss 0.01
An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a…
- risk 0.49cvss 7.5epss 0.01
A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this…
- risk 0.49cvss 7.5epss 0.01
Lexmark products through 2022-02-10 have Incorrect Access Control.
- risk 0.49cvss 7.5epss 0.02
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
- risk 0.49cvss 7.5epss 0.01
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
- risk 0.49cvss 7.5epss 0.02
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.
- risk 0.49cvss 7.5epss 0.07
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.
- risk 0.49cvss 7.5epss 0.02
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote…
- risk 0.49cvss 7.5epss 0.01
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.
- risk 0.49cvss 7.5epss 0.04
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
- risk 0.49cvss 7.5epss 0.03
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system…
- risk 0.49cvss 7.5epss 0.02
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.
- risk 0.49cvss 7.5epss 0.04
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam…
- risk 0.49cvss 7.5epss 0.01
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
- risk 0.49cvss 7.5epss 0.01
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.
- risk 0.49cvss 7.5epss 0.00
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
- risk 0.49cvss 7.5epss 0.01
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.
- risk 0.49cvss 7.5epss 0.01
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take a snapshot from the…