VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 115 of 169
  • CVE-2025-32063MedFeb 15, 2026
    risk 0.44cvss 6.8epss 0.00

    There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the…

  • CVE-2025-65731MedJan 8, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access…

  • CVE-2025-64770MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

  • CVE-2025-62674MedNov 20, 2025
    risk 0.44cvss 6.8epss 0.00

    The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

  • CVE-2025-60856MedOct 20, 2025
    risk 0.44cvss 6.8epss 0.00

    Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface and execute arbitrary commands with root privileges. NOTE: this is disputed by the Supplier…

  • CVE-2025-25736MedAug 26, 2025
    risk 0.44cvss 6.8epss 0.00

    Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated root shell access to the…

  • CVE-2025-32876MedJun 20, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the Short-Term Key (STK) can be easily guessed. This requires…

  • CVE-2025-24456MedJan 21, 2025
    risk 0.44cvss 6.7epss 0.00

    In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

  • CVE-2024-7726MedDec 20, 2024
    risk 0.44cvss 6.8epss 0.00

    There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can be accessed via an open JTAG debug port that is exposed on the drive’s circuit…

  • CVE-2022-25770HigSep 18, 2024
    risk 0.44cvss 7.8epss 0.00

    Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This vulnerability is mitigated by the fact that Mautic needs to be installed in a certain way to be vulnerable.

  • CVE-2024-35143MedAug 4, 2024
    risk 0.44cvss 6.7epss 0.00

    IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the…

  • CVE-2024-5143MedMay 23, 2024
    risk 0.44cvss 6.8epss 0.00

    A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.

  • CVE-2024-20391MedMay 15, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function.…

  • CVE-2023-25493MedApr 5, 2024
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.

  • CVE-2023-31033MedJan 12, 2024
    risk 0.44cvss 6.8epss 0.00

    NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information…

  • CVE-2023-20857MedFeb 28, 2023
    risk 0.44cvss 6.8epss 0.01

    VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.

  • CVE-2022-29402MedMay 25, 2022
    risk 0.44cvss 6.8epss 0.00

    TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.

  • CVE-2022-22309MedMay 24, 2022
    risk 0.44cvss 6.8epss 0.00

    The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 217095.

  • CVE-2021-20161MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.00

    Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection. No username or password is required and the user is given…

  • CVE-2021-33882MedAug 25, 2021
    risk 0.44cvss 6.8epss 0.01

    A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to reconfigure the device from an unknown source because of lack of authentication on proprietary networking commands.