VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 96 of 169
  • CVE-2023-31196HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensitive information of the affected products. Affected products and versions are as follows: AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier,…

  • CVE-2023-33247HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the…

  • CVE-2023-31227HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality.

  • CVE-2023-0116HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-31594HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.01

    IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.

  • CVE-2023-23444HigMay 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated…

  • CVE-2023-23906HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to execute some critical functions without authentication, e.g., rebooting the product.

  • CVE-2023-31444HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.

  • CVE-2023-29413HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.

  • CVE-2023-21979HigApr 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to…

  • CVE-2023-27747HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.01

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive information such as configurations and recordings.

  • CVE-2020-14140HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.01

    When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the…

  • CVE-2022-47703HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.01

    TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, and Hardware Version CPF906-V5.0_LCD_20200513.

  • CVE-2023-22803HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an attacker to change the PLC's mode arbitrarily.

  • CVE-2022-48300HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48299HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48289HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48288HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-43447HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.01

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.

  • CVE-2023-21856HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…