CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,982)
page 106 of 150| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4884 | Med | 0.42 | 6.5 | 0.00 | Oct 3, 2023 | An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication. | ||
| CVE-2023-35873 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its… | ||
| CVE-2023-35872 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its… | ||
| CVE-2023-34761 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2023 | An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter. | ||
| CVE-2022-4240 | Med | 0.42 | 6.5 | 0.01 | May 30, 2023 | Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1 | ||
| CVE-2023-28761 | Med | 0.42 | 6.5 | 0.00 | Apr 11, 2023 | In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and… | ||
| CVE-2022-48291 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2023 | The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-27983 | Med | 0.42 | 6.5 | 0.00 | Mar 21, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected… | ||
| CVE-2023-25570 | Hig | 0.42 | 7.5 | 0.01 | Feb 20, 2023 | Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service.… | ||
| CVE-2021-37234 | Med | 0.42 | 6.5 | 0.00 | Feb 3, 2023 | Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API. | ||
| CVE-2022-41505 | Med | 0.42 | 6.4 | 0.00 | Jan 23, 2023 | An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UART pins, interrupting the boot process, and setting an init=/bin/sh value. | ||
| CVE-2020-22661 | Med | 0.42 | 6.5 | 0.01 | Jan 20, 2023 | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)… | ||
| CVE-2022-35136 | Med | 0.42 | 6.5 | 0.01 | Oct 13, 2022 | Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests. | ||
| CVE-2022-31260 | Med | 0.42 | 6.5 | 0.02 | Jul 17, 2022 | In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value. | ||
| CVE-2022-29877 | Med | 0.42 | 6.5 | 0.01 | May 20, 2022 | A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions <… | ||
| CVE-2022-27495 | Med | 0.42 | 6.5 | 0.00 | May 5, 2022 | On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | ||
| CVE-2022-0922 | Med | 0.42 | 6.5 | 0.00 | Apr 1, 2022 | The software does not perform any authentication for critical system functionality. | ||
| CVE-2021-34870 | Med | 0.42 | 6.5 | 0.01 | Jan 25, 2022 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP… | ||
| CVE-2022-23945 | Hig | 0.42 | 7.5 | 0.04 | Jan 25, 2022 | Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | ||
| CVE-2021-43333 | Med | 0.42 | 6.5 | 0.01 | Jan 1, 2022 | The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration settings. |
- risk 0.42cvss 6.5epss 0.00
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
- risk 0.42cvss 6.5epss 0.01
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its…
- risk 0.42cvss 6.5epss 0.01
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its…
- risk 0.42cvss 6.5epss 0.01
An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter.
- risk 0.42cvss 6.5epss 0.01
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
- risk 0.42cvss 6.5epss 0.00
In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and…
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.42cvss 6.5epss 0.00
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected…
- risk 0.42cvss 7.5epss 0.01
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service.…
- risk 0.42cvss 6.5epss 0.00
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
- risk 0.42cvss 6.4epss 0.00
An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UART pins, interrupting the boot process, and setting an init=/bin/sh value.
- risk 0.42cvss 6.5epss 0.01
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…
- risk 0.42cvss 6.5epss 0.01
Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.
- risk 0.42cvss 6.5epss 0.02
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.
- risk 0.42cvss 6.5epss 0.01
A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions <…
- risk 0.42cvss 6.5epss 0.00
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- risk 0.42cvss 6.5epss 0.00
The software does not perform any authentication for critical system functionality.
- risk 0.42cvss 6.5epss 0.01
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP…
- risk 0.42cvss 7.5epss 0.04
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
- risk 0.42cvss 6.5epss 0.01
The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration settings.