VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 138 of 169
  • CVE-2019-0379MedOct 8, 2019
    risk 0.35cvss 5.3epss 0.01

    SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check

  • CVE-2019-8292MedOct 1, 2019
    risk 0.35cvss 5.3epss 0.02

    Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.

  • CVE-2019-13523MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.02

    In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without…

  • CVE-2019-11466MedSep 10, 2019
    risk 0.35cvss 5.3epss 0.01

    In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.

  • CVE-2019-9935MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    Various Lexmark products have Incorrect Access Control (issue 2 of 2).

  • CVE-2019-9934MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    Various Lexmark products have Incorrect Access Control (issue 1 of 2).

  • CVE-2019-15129MedAug 18, 2019
    risk 0.35cvss 5.3epss 0.01

    The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/pho…

  • CVE-2019-4337MedJul 1, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412.

  • CVE-2019-1897MedJun 20, 2019
    risk 0.35cvss 5.3epss 0.04

    A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affected router. The vulnerability is due to improper…

  • CVE-2019-1631MedJun 20, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection…

  • CVE-2019-1629MedJun 20, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily…

  • CVE-2019-0312MedJun 12, 2019
    risk 0.35cvss 5.3epss 0.01

    Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker could access landscape information like host names, ports…

  • CVE-2017-15123MedJun 12, 2019
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created…

  • CVE-2019-10046MedMay 31, 2019
    risk 0.35cvss 5.3epss 0.01

    An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

  • CVE-2019-11321MedApr 18, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.

  • CVE-2018-15466MedJan 11, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS…

  • CVE-2018-1757MedSep 7, 2018
    risk 0.35cvss 5.3epss 0.02

    IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive information due to missing authentication in IGI for the survey application. IBM X-Force ID: 148601.

  • CVE-2026-101004MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication.…

  • CVE-2026-100903MedSep 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched…

  • CVE-2026-93964MedSep 20, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack…