VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 89 of 150
  • CVE-2020-7953HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.

  • CVE-2019-19822HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.09

    A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT…

  • CVE-2020-3142HigJan 26, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile…

  • CVE-2011-4322HigJan 21, 2020
    risk 0.49cvss 7.5epss 0.01

    websitebaker prior to and including 2.8.1 has an authentication error in backup module.

  • CVE-2019-16731HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings.

  • CVE-2019-18311HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent…

  • CVE-2013-1793HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.01

    openstack-utils openstack-db has insecure password creation

  • CVE-2019-5163HigDec 3, 2019
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to…

  • CVE-2019-12389HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.

  • CVE-2019-18980HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.00

    On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use…

  • CVE-2019-17234HigNov 12, 2019
    risk 0.49cvss 7.5epss 0.03

    includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.

  • CVE-2019-18230HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.01

    Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.

  • CVE-2019-16906HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These…

  • CVE-2019-13549HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.01

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning…

  • CVE-2019-17511HigOct 14, 2019
    risk 0.49cvss 7.5epss 0.02

    There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network structure.

  • CVE-2019-17532HigOct 12, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because…

  • CVE-2019-17505HigOct 11, 2019
    risk 0.49cvss 7.5epss 0.02

    D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack.

  • CVE-2019-15018HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant.

  • CVE-2019-17232HigOct 7, 2019
    risk 0.49cvss 7.5epss 0.04

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

  • CVE-2019-15895HigSep 9, 2019
    risk 0.49cvss 7.5epss 0.02

    search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.