CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,362)
page 98 of 169| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36521 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2022 | Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts. | ||
| CVE-2022-37062 | Hig | 0.49 | 7.5 | 0.03 | Aug 18, 2022 | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite… | ||
| CVE-2022-30313 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected… | ||
| CVE-2022-30276 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)… | ||
| CVE-2021-34538 | Hig | 0.49 | 7.5 | 0.02 | Jul 16, 2022 | Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized… | ||
| CVE-2022-28771 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible. | ||
| CVE-2022-33138 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3).… | ||
| CVE-2022-21952 | Hig | 0.49 | 7.5 | 0.02 | Jun 22, 2022 | A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java… | ||
| CVE-2022-32157 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2022 | Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients… | ||
| CVE-2022-32557 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2022 | An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers. | ||
| CVE-2021-42893 | Hig | 0.49 | 7.5 | 0.01 | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg. | ||
| CVE-2021-42891 | Hig | 0.49 | 7.5 | 0.01 | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. | ||
| CVE-2021-42889 | Hig | 0.49 | 7.5 | 0.01 | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization. | ||
| CVE-2022-27169 | Hig | 0.49 | 7.5 | 0.02 | May 25, 2022 | An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to… | ||
| CVE-2022-26303 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of… | ||
| CVE-2022-26043 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a… | ||
| CVE-2022-26026 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2022 | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this… | ||
| CVE-2022-24935 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | Lexmark products through 2022-02-10 have Incorrect Access Control. | ||
| CVE-2022-23345 | Hig | 0.49 | 7.5 | 0.02 | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control. | ||
| CVE-2022-26267 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. |
- risk 0.49cvss 7.5epss 0.01
Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.
- risk 0.49cvss 7.5epss 0.03
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite…
- risk 0.49cvss 7.5epss 0.01
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected…
- risk 0.49cvss 7.5epss 0.01
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)…
- risk 0.49cvss 7.5epss 0.02
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized…
- risk 0.49cvss 7.5epss 0.01
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3).…
- risk 0.49cvss 7.5epss 0.02
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java…
- risk 0.49cvss 7.5epss 0.01
Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
- risk 0.49cvss 7.5epss 0.01
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
- risk 0.49cvss 7.5epss 0.01
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
- risk 0.49cvss 7.5epss 0.01
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
- risk 0.49cvss 7.5epss 0.02
An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to…
- risk 0.49cvss 7.5epss 0.01
An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of…
- risk 0.49cvss 7.5epss 0.01
An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a…
- risk 0.49cvss 7.5epss 0.01
A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this…
- risk 0.49cvss 7.5epss 0.01
Lexmark products through 2022-02-10 have Incorrect Access Control.
- risk 0.49cvss 7.5epss 0.02
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
- risk 0.49cvss 7.5epss 0.01
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.