VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 123 of 149
  • CVE-2022-31701MedDec 14, 2022
    risk 0.34cvss 5.3epss 0.01

    VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

  • CVE-2022-42473MedNov 2, 2022
    risk 0.34cvss 5.3epss 0.00

    A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.

  • CVE-2021-36200MedJul 22, 2022
    risk 0.34cvss 5.3epss 0.01

    Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.

  • CVE-2020-26599MedOct 6, 2020
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentication. The Samsung ID is SVE-2020-17079 (October 2020).

  • CVE-2020-9062MedAug 21, 2020
    risk 0.34cvss 5.3epss 0.00

    Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery…

  • CVE-2019-20624MedMar 24, 2020
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Samsung ID is SVE-2018-12981 (February 2019).

  • CVE-2019-20532MedMar 24, 2020
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is SVE-2019-15800 (December 2019).

  • CVE-2026-42303MedMay 12, 2026
    risk 0.33cvss epss 0.00

    Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request…

  • CVE-2026-4582MedMar 23, 2026
    risk 0.33cvss 5.0epss 0.00

    A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the…

  • CVE-2026-2756MedMar 21, 2026
    risk 0.33cvss 5.0epss 0.00

    A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is…

  • CVE-2025-60251MedSep 26, 2025
    risk 0.33cvss 5.0epss 0.00

    Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.

  • CVE-2025-5719MedJun 6, 2025
    risk 0.33cvss epss 0.00

    The wallet has an authentication bypass vulnerability that allows access to specific pages.

  • CVE-2025-44039MedMay 13, 2025
    risk 0.33cvss 5.1epss 0.00

    CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details…

  • CVE-2024-57055MedFeb 18, 2025
    risk 0.33cvss 5.0epss 0.00

    Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and…

  • CVE-2024-6895MedJul 19, 2024
    risk 0.33cvss epss 0.00

    Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify…

  • CVE-2024-22326MedJun 6, 2024
    risk 0.33cvss 5.0epss 0.00

    IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection.   IBM X-Force ID: 279518.

  • CVE-2022-31022MedJun 1, 2022
    risk 0.33cvss 6.2epss 0.00

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP…

  • CVE-2025-25265MedJun 16, 2025
    risk 0.32cvss 4.9epss 0.00

    A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure.

  • CVE-2024-22513MedMar 16, 2024
    risk 0.32cvss 5.5epss 0.01

    djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.

  • CVE-2022-36780MedSep 13, 2022
    risk 0.32cvss 4.9epss 0.00

    Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authenticate to the system. Attacker sends crafted URL to the system: ip:port//V=2;ChannellD=number;Ext=number;Command=startLM;Client=number;…