VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 112 of 150
  • CVE-2023-37495MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.00

    Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…

  • CVE-2024-21306MedJan 9, 2024
    risk 0.38cvss 5.7epss 0.06

    Microsoft Bluetooth Driver Spoofing Vulnerability

  • CVE-2023-6368MedDec 14, 2023
    risk 0.38cvss 5.9epss 0.01

    In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.

  • CVE-2023-27256MedOct 25, 2023
    risk 0.38cvss 5.8epss 0.01

    Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers.

  • CVE-2023-43045MedOct 23, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.

  • CVE-2023-41333MedSep 27, 2023
    risk 0.38cvss 6.9epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to create or modify CiliumNetworkPolicy objects in a particular namespace is able to affect traffic on an entire Cilium cluster, potentially bypassing policy…

  • CVE-2023-39436MedAug 8, 2023
    risk 0.38cvss 5.8epss 0.00

    SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the…

  • CVE-2022-3738MedJan 19, 2023
    risk 0.38cvss 5.9epss 0.01

    The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be…

  • CVE-2022-2552MedAug 22, 2022
    risk 0.38cvss 5.3epss 0.11

    The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

  • CVE-2022-34767MedJul 21, 2022
    risk 0.38cvss 5.9epss 0.01

    Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.

  • CVE-2021-20150MedDec 30, 2021
    risk 0.38cvss 5.3epss 0.40

    Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

  • CVE-2021-22784MedJul 21, 2021
    risk 0.38cvss 5.7epss 0.12

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.

  • CVE-2021-28124MedApr 2, 2021
    risk 0.38cvss 5.9epss 0.01

    A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Missing server authentication in impacted versions can allow an attacker to Man-in-the-middle (MITM) support channel UI session to…

  • CVE-2020-3448MedAug 17, 2020
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authentication and access internal services that are running on an affected device. The vulnerability is due to insufficient enforcement…

  • CVE-2018-16758MedOct 10, 2018
    risk 0.38cvss 5.9epss 0.01

    Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.

  • CVE-2011-4190MedJun 8, 2018
    risk 0.38cvss 5.9epss 0.01

    The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server…

  • CVE-2026-45610MedMay 29, 2026
    risk 0.37cvss 5.7epss 0.00

    WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the…

  • CVE-2026-32326MedMar 25, 2026
    risk 0.37cvss 5.7epss 0.00

    SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.

  • CVE-2026-22174MedMar 18, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback port can intercept CDP reachability probes…

  • CVE-2026-28450MedMar 5, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/channels/nostr/:accountId/profile/import that allow reading and modifying Nostr profiles without gateway…