CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,362)
page 138 of 169| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0379 | Med | 0.35 | 5.3 | 0.01 | Oct 8, 2019 | SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check | ||
| CVE-2019-8292 | Med | 0.35 | 5.3 | 0.02 | Oct 1, 2019 | Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion. | ||
| CVE-2019-13523 | Med | 0.35 | 5.3 | 0.02 | Sep 26, 2019 | In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without… | ||
| CVE-2019-11466 | Med | 0.35 | 5.3 | 0.01 | Sep 10, 2019 | In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access. | ||
| CVE-2019-9935 | Med | 0.35 | 5.3 | 0.01 | Aug 28, 2019 | Various Lexmark products have Incorrect Access Control (issue 2 of 2). | ||
| CVE-2019-9934 | Med | 0.35 | 5.3 | 0.01 | Aug 28, 2019 | Various Lexmark products have Incorrect Access Control (issue 1 of 2). | ||
| CVE-2019-15129 | Med | 0.35 | 5.3 | 0.01 | Aug 18, 2019 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/pho… | ||
| CVE-2019-4337 | Med | 0.35 | 5.3 | 0.01 | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412. | ||
| CVE-2019-1897 | Med | 0.35 | 5.3 | 0.04 | Jun 20, 2019 | A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affected router. The vulnerability is due to improper… | ||
| CVE-2019-1631 | Med | 0.35 | 5.3 | 0.02 | Jun 20, 2019 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection… | ||
| CVE-2019-1629 | Med | 0.35 | 5.3 | 0.02 | Jun 20, 2019 | A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily… | ||
| CVE-2019-0312 | Med | 0.35 | 5.3 | 0.01 | Jun 12, 2019 | Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports… | ||
| CVE-2017-15123 | Med | 0.35 | 5.3 | 0.01 | Jun 12, 2019 | A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created… | ||
| CVE-2019-10046 | Med | 0.35 | 5.3 | 0.01 | May 31, 2019 | An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information. | ||
| CVE-2019-11321 | Med | 0.35 | 5.3 | 0.01 | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices. | ||
| CVE-2018-15466 | Med | 0.35 | 5.3 | 0.02 | Jan 11, 2019 | A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS… | ||
| CVE-2018-1757 | Med | 0.35 | 5.3 | 0.02 | Sep 7, 2018 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601. | ||
| CVE-2026-101004 | Med | 0.34 | 5.3 | 0.01 | Sep 28, 2026 | A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication.… | ||
| CVE-2026-100903 | — | Med | 0.34 | 5.3 | 0.00 | Sep 28, 2026 | A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched… | |
| CVE-2026-93964 | Med | 0.34 | 5.3 | 0.00 | Sep 20, 2026 | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack… |
- risk 0.35cvss 5.3epss 0.01
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check
- risk 0.35cvss 5.3epss 0.02
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.
- risk 0.35cvss 5.3epss 0.02
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without…
- risk 0.35cvss 5.3epss 0.01
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
- risk 0.35cvss 5.3epss 0.01
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
- risk 0.35cvss 5.3epss 0.01
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
- risk 0.35cvss 5.3epss 0.01
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/pho…
- risk 0.35cvss 5.3epss 0.01
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412.
- risk 0.35cvss 5.3epss 0.04
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affected router. The vulnerability is due to improper…
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection…
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily…
- risk 0.35cvss 5.3epss 0.01
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports…
- risk 0.35cvss 5.3epss 0.01
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created…
- risk 0.35cvss 5.3epss 0.01
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS…
- risk 0.35cvss 5.3epss 0.02
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601.
- risk 0.34cvss 5.3epss 0.01
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication.…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack…