VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 88 of 150
  • CVE-2020-10972HigMay 7, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml page with the variable syspasswd). Affected Devices: Wavlink…

  • CVE-2020-12478HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.08

    TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

  • CVE-2020-10641HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a…

  • CVE-2020-12266HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can…

  • CVE-2018-21041HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The Samsung ID is SVE-2018-13057 (December 2018).

  • CVE-2020-11599HigApr 6, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SMTP user.

  • CVE-2020-9349HigApr 2, 2020
    risk 0.49cvss 7.5epss 0.01

    The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password.

  • CVE-2020-10833HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).

  • CVE-2020-10874HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Motorola FX9500 devices allow remote attackers to read database files.

  • CVE-2019-15655HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving the configuration file. The password is stored in cleartext.

  • CVE-2019-15654HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.02

    Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doesn't require any authentication and will lead to saving the DBconfig.cfg file. At the end of the…

  • CVE-2020-9325HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

  • CVE-2019-13194HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.

  • CVE-2019-13205HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected.…

  • CVE-2020-9544HigMar 5, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their choice.

  • CVE-2019-19226HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.03

    A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable MAC address filtering by submitting a crafted Forms/WlanMacFilter_1 POST request without being authenticated on the admin…

  • CVE-2019-19225HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.03

    A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers without being authenticated on the admin interface by submitting a crafted Forms/dns_1 POST request.

  • CVE-2019-19224HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.03

    A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the configuration (binary file) settings by submitting a rom-0 GET request without being authenticated on the admin interface.

  • CVE-2015-5201HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.01

    VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and…

  • CVE-2020-6186HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.01

    SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host Agent, leading to Denial of Service.