VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 95 of 169
  • CVE-2023-27376HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

  • CVE-2023-27375HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

  • CVE-2023-27259HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.

  • CVE-2023-27258HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.

  • CVE-2023-27257HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers.

  • CVE-2023-26580HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.

  • CVE-2023-26576HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

  • CVE-2023-26575HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

  • CVE-2023-26574HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

  • CVE-2023-26571HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.

  • CVE-2023-26570HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

  • CVE-2023-39981HigSep 2, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.

  • CVE-2023-38030HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

  • CVE-2023-38422HigAug 23, 2023
    risk 0.49cvss 7.5epss 0.01

    Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could allow an attacker to download and export sensitive data.

  • CVE-2023-4335HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

  • CVE-2023-4334HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

  • CVE-2023-39380HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

  • CVE-2023-38379HigJul 16, 2023
    risk 0.49cvss 7.5epss 0.01

    The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero…

  • CVE-2022-48496HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2022-48494HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.