VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 106 of 150
  • CVE-2023-4884MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

  • CVE-2023-35873MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its…

  • CVE-2023-35872MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its…

  • CVE-2023-34761MedJun 28, 2023
    risk 0.42cvss 6.5epss 0.01

    An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter.

  • CVE-2022-4240MedMay 30, 2023
    risk 0.42cvss 6.5epss 0.01

    Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1

  • CVE-2023-28761MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.00

    In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and…

  • CVE-2022-48291MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-27983MedMar 21, 2023
    risk 0.42cvss 6.5epss 0.00

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected…

  • CVE-2023-25570HigFeb 20, 2023
    risk 0.42cvss 7.5epss 0.01

    Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service.…

  • CVE-2021-37234MedFeb 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.

  • CVE-2022-41505MedJan 23, 2023
    risk 0.42cvss 6.4epss 0.00

    An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UART pins, interrupting the boot process, and setting an init=/bin/sh value.

  • CVE-2020-22661MedJan 20, 2023
    risk 0.42cvss 6.5epss 0.01

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2022-35136MedOct 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

  • CVE-2022-31260MedJul 17, 2022
    risk 0.42cvss 6.5epss 0.02

    In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.

  • CVE-2022-29877MedMay 20, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions <…

  • CVE-2022-27495MedMay 5, 2022
    risk 0.42cvss 6.5epss 0.00

    On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2022-0922MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.00

    The software does not perform any authentication for critical system functionality.

  • CVE-2021-34870MedJan 25, 2022
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP…

  • CVE-2022-23945HigJan 25, 2022
    risk 0.42cvss 7.5epss 0.04

    Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

  • CVE-2021-43333MedJan 1, 2022
    risk 0.42cvss 6.5epss 0.01

    The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration settings.