VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 87 of 150
  • CVE-2020-25966HigOct 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID…

  • CVE-2020-26876HigOct 7, 2020
    risk 0.49cvss 7.5epss 0.11

    The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020. This occurs because show_in_rest is enabled for custom…

  • CVE-2020-26061HigOct 5, 2020
    risk 0.49cvss 7.5epss 0.04

    ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker…

  • CVE-2020-12127HigOct 2, 2020
    risk 0.49cvss 7.5epss 0.07

    An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

  • CVE-2018-1501HigAug 26, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-Force ID: 141226.

  • CVE-2020-17475HigAug 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.

  • CVE-2020-6309HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.02

    SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service.

  • CVE-2020-15127HigAug 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown…

  • CVE-2020-15894HigJul 22, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin…

  • CVE-2020-10605HigJul 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.

  • CVE-2020-10044HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the network could be able to install specially crafted firmware to the device.

  • CVE-2020-5910HigJul 2, 2020
    risk 0.49cvss 7.5epss 0.01

    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.

  • CVE-2020-3402HigJul 2, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not…

  • CVE-2020-15336HigJun 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.

  • CVE-2020-15335HigJun 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.

  • CVE-2020-11961HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication

  • CVE-2020-14048HigJun 12, 2020
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.

  • CVE-2020-12877HigMay 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.

  • CVE-2020-10974HigMay 7, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6,…

  • CVE-2020-10973HigMay 7, 2020
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is…