VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 116 of 169
  • CVE-2021-32794MedJul 26, 2021
    risk 0.44cvss 6.8epss 0.01

    ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `IPCPassword` from the resulting config…

  • CVE-2021-26928MedJun 4, 2021
    risk 0.44cvss 6.8epss 0.01

    BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route…

  • CVE-2021-22316MedJun 3, 2021
    risk 0.44cvss 6.8epss 0.00

    There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerability can compromise the device's data security and…

  • CVE-2021-1499MedMay 6, 2021
    risk 0.44cvss 5.3epss 0.80

    A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An attacker could exploit…

  • CVE-2021-20262MedMar 9, 2021
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to…

  • CVE-2020-15483MedAug 26, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.

  • CVE-2020-1813MedJun 15, 2020
    risk 0.44cvss 6.8epss 0.00

    HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authentication of specific interface, in specific scenario attackers could access specific interface without authentication. Successful…

  • CVE-2020-10263MedApr 8, 2020
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) read Wi-Fi SSID or password, (ii) read the dialogue text files between users and XIAOMI XIAOAI speaker Pro LX06, (iii) use…

  • CVE-2019-16258MedMar 20, 2020
    risk 0.44cvss 6.8epss 0.00

    The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.

  • CVE-2019-8449MedSep 11, 2019
    risk 0.44cvss 5.3epss 0.85

    The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

  • CVE-2014-7271HigMar 8, 2018
    risk 0.44cvss 7.8epss 0.00

    Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

  • CVE-2017-17746MedDec 20, 2017
    risk 0.44cvss 6.8epss 0.02

    Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a…

  • CVE-2017-8156MedNov 22, 2017
    risk 0.44cvss 6.8epss 0.00

    The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit and log in to the CPE without authentication. Successful…

  • CVE-2026-42283HigMay 14, 2026
    risk 0.43cvss 7.7epss 0.00

    DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the…

  • CVE-2026-44338HigMay 8, 2026
    risk 0.43cvss 7.3epss 0.01

    PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured…

  • CVE-2026-32064HigMar 21, 2026
    risk 0.43cvss 7.7epss 0.01

    OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to…

  • CVE-2026-28468HigMar 5, 2026
    risk 0.43cvss 7.7epss 0.00

    OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests without requiring gateway authentication, allowing local attackers to access browser control endpoints. A local attacker can enumerate…

  • CVE-2025-42875MedDec 9, 2025
    risk 0.43cvss 6.6epss 0.00

    The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and…

  • CVE-2024-57725MedFeb 14, 2025
    risk 0.43cvss 6.5epss 0.06

    An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.

  • CVE-2024-45229MedSep 20, 2024
    risk 0.43cvss 6.6epss 0.01

    The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one…