CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,362)
page 135 of 169| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45424 | Med | 0.35 | 5.3 | 0.01 | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface. | ||
| CVE-2022-4228 | Med | 0.35 | 5.3 | 0.01 | Nov 30, 2022 | A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file /bsms_ci/index.php/user/edit_user/. The manipulation of the argument password leads to information disclosure. It is possible to… | ||
| CVE-2022-30515 | Med | 0.35 | 5.3 | 0.01 | Nov 8, 2022 | ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration. | ||
| CVE-2022-20830 | Med | 0.35 | 5.3 | 0.01 | Oct 10, 2022 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI… | ||
| CVE-2021-36200 | Med | 0.35 | 5.3 | 0.01 | Jul 22, 2022 | Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users. | ||
| CVE-2022-1598 | Med | 0.35 | 5.3 | 0.05 | Jun 8, 2022 | The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site. | ||
| CVE-2022-26971 | Med | 0.35 | 5.3 | 0.01 | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication. | ||
| CVE-2022-29883 | Med | 0.35 | 5.3 | 0.01 | May 20, 2022 | A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files without authentication. | ||
| CVE-2022-29881 | Med | 0.35 | 5.3 | 0.01 | May 20, 2022 | A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer views. This could allow unauthenticated users to extract internal configuration… | ||
| CVE-2022-0424 | Med | 0.35 | 5.3 | 0.03 | May 9, 2022 | The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users | ||
| CVE-2022-0140 | Med | 0.35 | 5.3 | 0.04 | Apr 12, 2022 | The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. | ||
| CVE-2022-24820 | Med | 0.35 | 5.3 | 0.01 | Apr 8, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions… | ||
| CVE-2022-25245 | Med | 0.35 | 5.3 | 0.01 | Apr 5, 2022 | Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. | ||
| CVE-2020-14479 | Med | 0.35 | 5.3 | 0.01 | Apr 1, 2022 | Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server | ||
| CVE-2022-0188 | Med | 0.35 | 5.3 | 0.02 | Feb 14, 2022 | The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout. | ||
| CVE-2022-24111 | Med | 0.35 | 5.3 | 0.01 | Feb 10, 2022 | In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known. | ||
| CVE-2022-22809 | Med | 0.35 | 5.3 | 0.01 | Feb 9, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser… | ||
| CVE-2021-33843 | Med | 0.35 | 5.3 | 0.01 | Jan 21, 2022 | Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings. | ||
| CVE-2021-43974 | Med | 0.35 | 5.3 | 0.01 | Jan 11, 2022 | An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to… | ||
| CVE-2021-33259 | Med | 0.35 | 5.3 | 0.02 | Oct 31, 2021 | Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history. |
- risk 0.35cvss 5.3epss 0.01
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface.
- risk 0.35cvss 5.3epss 0.01
A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file /bsms_ci/index.php/user/edit_user/. The manipulation of the argument password leads to information disclosure. It is possible to…
- risk 0.35cvss 5.3epss 0.01
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI…
- risk 0.35cvss 5.3epss 0.01
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
- risk 0.35cvss 5.3epss 0.05
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.
- risk 0.35cvss 5.3epss 0.01
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
- risk 0.35cvss 5.3epss 0.01
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files without authentication.
- risk 0.35cvss 5.3epss 0.01
A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer views. This could allow unauthenticated users to extract internal configuration…
- risk 0.35cvss 5.3epss 0.03
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
- risk 0.35cvss 5.3epss 0.04
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
- risk 0.35cvss 5.3epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions…
- risk 0.35cvss 5.3epss 0.01
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
- risk 0.35cvss 5.3epss 0.01
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
- risk 0.35cvss 5.3epss 0.02
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- risk 0.35cvss 5.3epss 0.01
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.
- risk 0.35cvss 5.3epss 0.01
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser…
- risk 0.35cvss 5.3epss 0.01
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to…
- risk 0.35cvss 5.3epss 0.02
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.