CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,982)
page 117 of 150| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24820 | Med | 0.35 | 5.3 | 0.01 | Apr 8, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions… | ||
| CVE-2022-25245 | Med | 0.35 | 5.3 | 0.01 | Apr 5, 2022 | Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. | ||
| CVE-2020-14479 | Med | 0.35 | 5.3 | 0.01 | Apr 1, 2022 | Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server | ||
| CVE-2022-0188 | Med | 0.35 | 5.3 | 0.02 | Feb 14, 2022 | The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout. | ||
| CVE-2022-24111 | Med | 0.35 | 5.3 | 0.01 | Feb 10, 2022 | In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known. | ||
| CVE-2022-22809 | Med | 0.35 | 5.3 | 0.01 | Feb 9, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser… | ||
| CVE-2021-33843 | Med | 0.35 | 5.3 | 0.01 | Jan 21, 2022 | Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings. | ||
| CVE-2021-43974 | Med | 0.35 | 5.3 | 0.01 | Jan 11, 2022 | An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to… | ||
| CVE-2021-33259 | Med | 0.35 | 5.3 | 0.02 | Oct 31, 2021 | Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history. | ||
| CVE-2021-41976 | Med | 0.35 | 5.3 | 0.01 | Oct 8, 2021 | Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in. | ||
| CVE-2021-41568 | Med | 0.35 | 5.3 | 0.01 | Oct 8, 2021 | Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system. | ||
| CVE-2019-10941 | Med | 0.35 | 5.3 | 0.01 | Sep 14, 2021 | A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network… | ||
| CVE-2021-27668 | Med | 0.35 | 5.3 | 0.01 | Aug 31, 2021 | HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3. | ||
| CVE-2020-21936 | Med | 0.35 | 5.3 | 0.01 | Jul 21, 2021 | An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication. | ||
| CVE-2021-20107 | Med | 0.35 | 5.4 | 0.01 | Jun 30, 2021 | There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use… | ||
| CVE-2020-20472 | Med | 0.35 | 5.3 | 0.01 | Jun 21, 2021 | White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users of the current site. | ||
| CVE-2021-32659 | Med | 0.35 | 6.5 | 0.01 | Jun 16, 2021 | Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge`… | ||
| CVE-2020-25634 | Med | 0.35 | 5.4 | 0.01 | May 26, 2021 | A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected. | ||
| CVE-2021-27571 | Med | 0.35 | 5.3 | 0.01 | May 7, 2021 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic. | ||
| CVE-2021-27570 | Med | 0.35 | 5.3 | 0.01 | May 7, 2021 | An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected by any authentication logic. |
- risk 0.35cvss 5.3epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions…
- risk 0.35cvss 5.3epss 0.01
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
- risk 0.35cvss 5.3epss 0.01
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
- risk 0.35cvss 5.3epss 0.02
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- risk 0.35cvss 5.3epss 0.01
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.
- risk 0.35cvss 5.3epss 0.01
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser…
- risk 0.35cvss 5.3epss 0.01
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to…
- risk 0.35cvss 5.3epss 0.02
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
- risk 0.35cvss 5.3epss 0.01
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
- risk 0.35cvss 5.3epss 0.01
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system.
- risk 0.35cvss 5.3epss 0.01
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network…
- risk 0.35cvss 5.3epss 0.01
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
- risk 0.35cvss 5.3epss 0.01
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.
- risk 0.35cvss 5.4epss 0.01
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use…
- risk 0.35cvss 5.3epss 0.01
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users of the current site.
- risk 0.35cvss 6.5epss 0.01
Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge`…
- risk 0.35cvss 5.4epss 0.01
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected by any authentication logic.