CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,982)
page 89 of 150| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7953 | Hig | 0.49 | 7.5 | 0.01 | Feb 6, 2020 | An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option. | ||
| CVE-2019-19822 | Hig | 0.49 | 7.5 | 0.09 | Jan 27, 2020 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT… | ||
| CVE-2020-3142 | Hig | 0.49 | 7.5 | 0.01 | Jan 26, 2020 | A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile… | ||
| CVE-2011-4322 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2020 | websitebaker prior to and including 2.8.1 has an authentication error in backup module. | ||
| CVE-2019-16731 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2019 | The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings. | ||
| CVE-2019-18311 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2019 | A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent… | ||
| CVE-2013-1793 | Hig | 0.49 | 7.5 | 0.01 | Dec 10, 2019 | openstack-utils openstack-db has insecure password creation | ||
| CVE-2019-5163 | Hig | 0.49 | 7.5 | 0.02 | Dec 3, 2019 | An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to… | ||
| CVE-2019-12389 | Hig | 0.49 | 7.5 | 0.02 | Dec 2, 2019 | Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010. | ||
| CVE-2019-18980 | Hig | 0.49 | 7.5 | 0.00 | Nov 14, 2019 | On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use… | ||
| CVE-2019-17234 | Hig | 0.49 | 7.5 | 0.03 | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion. | ||
| CVE-2019-18230 | Hig | 0.49 | 7.5 | 0.01 | Oct 31, 2019 | Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP. | ||
| CVE-2019-16906 | Hig | 0.49 | 7.5 | 0.02 | Oct 31, 2019 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These… | ||
| CVE-2019-13549 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2019 | Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning… | ||
| CVE-2019-17511 | Hig | 0.49 | 7.5 | 0.02 | Oct 14, 2019 | There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network structure. | ||
| CVE-2019-17532 | Hig | 0.49 | 7.5 | 0.02 | Oct 12, 2019 | An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because… | ||
| CVE-2019-17505 | Hig | 0.49 | 7.5 | 0.02 | Oct 11, 2019 | D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack. | ||
| CVE-2019-15018 | Hig | 0.49 | 7.5 | 0.01 | Oct 9, 2019 | A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant. | ||
| CVE-2019-17232 | Hig | 0.49 | 7.5 | 0.04 | Oct 7, 2019 | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import. | ||
| CVE-2019-15895 | Hig | 0.49 | 7.5 | 0.02 | Sep 9, 2019 | search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.
- risk 0.49cvss 7.5epss 0.09
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT…
- risk 0.49cvss 7.5epss 0.01
A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile…
- risk 0.49cvss 7.5epss 0.01
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
- risk 0.49cvss 7.5epss 0.01
The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent…
- risk 0.49cvss 7.5epss 0.01
openstack-utils openstack-db has insecure password creation
- risk 0.49cvss 7.5epss 0.02
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to…
- risk 0.49cvss 7.5epss 0.02
Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.
- risk 0.49cvss 7.5epss 0.00
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use…
- risk 0.49cvss 7.5epss 0.03
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
- risk 0.49cvss 7.5epss 0.01
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These…
- risk 0.49cvss 7.5epss 0.01
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning…
- risk 0.49cvss 7.5epss 0.02
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network structure.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because…
- risk 0.49cvss 7.5epss 0.02
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack.
- risk 0.49cvss 7.5epss 0.01
A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant.
- risk 0.49cvss 7.5epss 0.04
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
- risk 0.49cvss 7.5epss 0.02
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.