VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 90 of 150
  • CVE-2019-13406HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.02

    A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.

  • CVE-2019-15506HigAug 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send properly formatted requests to the web application and download sensitive files and information.…

  • CVE-2019-14511HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

  • CVE-2019-12634HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The…

  • CVE-2019-1010136HigJul 19, 2019
    risk 0.49cvss 7.5epss 0.02

    ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users…

  • CVE-2019-13338HigJul 9, 2019
    risk 0.49cvss 7.5epss 0.02

    In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.

  • CVE-2019-11020HigJul 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.

  • CVE-2019-11019HigJul 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by visiting easily guessable exportpdf/all_claim_detail.php?claim_id= URLs.

  • CVE-2019-3411HigJun 11, 2019
    risk 0.49cvss 7.5epss 0.01

    All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to obtain sensitive information about the affected components.

  • CVE-2019-6451HigJun 6, 2019
    risk 0.49cvss 7.5epss 0.02

    On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.

  • CVE-2019-9105HigMay 31, 2019
    risk 0.49cvss 7.5epss 0.02

    The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customu…

  • CVE-2019-9727HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.02

    Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users. This vulnerability can be exploited by unauthenticated attackers with access to the web…

  • CVE-2019-7404HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.

  • CVE-2019-10946HigApr 10, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.

  • CVE-2019-3941HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

  • CVE-2019-6542HigMar 28, 2019
    risk 0.49cvss 7.5epss 0.02

    ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to initiate a remote reboot, which may be used to cause a denial of service condition.

  • CVE-2019-7642HigMar 25, 2019
    risk 0.49cvss 7.5epss 0.03

    D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04),…

  • CVE-2019-10042HigMar 25, 2019
    risk 0.49cvss 7.5epss 0.02

    The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.

  • CVE-2019-3917HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.02

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request.

  • CVE-2019-9484HigMar 1, 2019
    risk 0.49cvss 7.5epss 0.02

    The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."