VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 85 of 150
  • CVE-2022-26303HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of…

  • CVE-2022-26043HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a…

  • CVE-2022-26026HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this…

  • CVE-2022-24935HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Lexmark products through 2022-02-10 have Incorrect Access Control.

  • CVE-2022-23345HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.02

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

  • CVE-2022-26267HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.

  • CVE-2021-44262HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.

  • CVE-2021-44260HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.07

    A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.

  • CVE-2022-25250HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.02

    When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote…

  • CVE-2022-25508HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.

  • CVE-2021-46371HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.04

    antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

  • CVE-2021-34543HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.03

    The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system…

  • CVE-2021-38283HigNov 29, 2021
    risk 0.49cvss 7.5epss 0.02

    Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.

  • CVE-2021-37624HigOct 25, 2021
    risk 0.49cvss 7.5epss 0.04

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam…

  • CVE-2021-41975HigOct 8, 2021
    risk 0.49cvss 7.5epss 0.01

    TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.

  • CVE-2021-22012HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

  • CVE-2020-21934HigJul 21, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.

  • CVE-2021-20474HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.00

    IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

  • CVE-2021-22322HigJun 3, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

  • CVE-2021-31793HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take a snapshot from the…