VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 98 of 169
  • CVE-2022-36521HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

  • CVE-2022-37062HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.03

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite…

  • CVE-2022-30313HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected…

  • CVE-2022-30276HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)…

  • CVE-2021-34538HigJul 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized…

  • CVE-2022-28771HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.

  • CVE-2022-33138HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3).…

  • CVE-2022-21952HigJun 22, 2022
    risk 0.49cvss 7.5epss 0.02

    A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java…

  • CVE-2022-32157HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients…

  • CVE-2022-32557HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.

  • CVE-2021-42893HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.

  • CVE-2021-42891HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.

  • CVE-2021-42889HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.

  • CVE-2022-27169HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to…

  • CVE-2022-26303HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of…

  • CVE-2022-26043HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a…

  • CVE-2022-26026HigMay 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this…

  • CVE-2022-24935HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Lexmark products through 2022-02-10 have Incorrect Access Control.

  • CVE-2022-23345HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.02

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

  • CVE-2022-26267HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.