VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 100 of 150
  • CVE-2023-31033MedJan 12, 2024
    risk 0.44cvss 6.8epss 0.00

    NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information…

  • CVE-2023-20857MedFeb 28, 2023
    risk 0.44cvss 6.8epss 0.01

    VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.

  • CVE-2022-29402MedMay 25, 2022
    risk 0.44cvss 6.8epss 0.00

    TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.

  • CVE-2022-22309MedMay 24, 2022
    risk 0.44cvss 6.8epss 0.00

    The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 217095.

  • CVE-2021-20161MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.00

    Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection. No username or password is required and the user is given…

  • CVE-2021-33882MedAug 25, 2021
    risk 0.44cvss 6.8epss 0.01

    A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to reconfigure the device from an unknown source because of lack of authentication on proprietary networking commands.

  • CVE-2021-26928MedJun 4, 2021
    risk 0.44cvss 6.8epss 0.01

    BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route…

  • CVE-2021-22316MedJun 3, 2021
    risk 0.44cvss 6.8epss 0.00

    There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerability can compromise the device's data security and…

  • CVE-2021-1499MedMay 6, 2021
    risk 0.44cvss 5.3epss 0.80

    A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An attacker could exploit…

  • CVE-2021-20262MedMar 9, 2021
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to…

  • CVE-2020-15483MedAug 26, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.

  • CVE-2020-1813MedJun 15, 2020
    risk 0.44cvss 6.8epss 0.00

    HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authentication of specific interface, in specific scenario attackers could access specific interface without authentication. Successful…

  • CVE-2020-10263MedApr 8, 2020
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) read Wi-Fi SSID or password, (ii) read the dialogue text files between users and XIAOMI XIAOAI speaker Pro LX06, (iii) use…

  • CVE-2019-16258MedMar 20, 2020
    risk 0.44cvss 6.8epss 0.00

    The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.

  • CVE-2019-8449MedSep 11, 2019
    risk 0.44cvss 5.3epss 0.85

    The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

  • CVE-2014-7271HigMar 8, 2018
    risk 0.44cvss 7.8epss 0.00

    Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

  • CVE-2017-17746MedDec 20, 2017
    risk 0.44cvss 6.8epss 0.02

    Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a…

  • CVE-2017-8156MedNov 22, 2017
    risk 0.44cvss 6.8epss 0.00

    The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit and log in to the CPE without authentication. Successful…

  • CVE-2026-42283HigMay 14, 2026
    risk 0.43cvss 7.7epss 0.00

    DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the…

  • CVE-2026-44338HigMay 8, 2026
    risk 0.43cvss 7.3epss 0.29

    PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured…