VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 67 of 169
  • CVE-2024-48882HigDec 1, 2025
    risk 0.56cvss 8.6epss 0.01

    A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.

  • CVE-2025-43994HigOct 24, 2025
    risk 0.56cvss 8.6epss 0.01

    Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2025-61673HigOct 3, 2025
    risk 0.56cvss 8.6epss 0.00

    Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability when configured to use OAuth 2.0 Bearer Token authentication. If a request is sent without an Authorization header, the token…

  • CVE-2025-34231HigSep 29, 2025
    risk 0.56cvss 8.6epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind and non-blind server-side request forgery (SSRF) vulnerability. The '/var/www/app/console_release/hp/badgeSetup…

  • CVE-2025-34228HigSep 29, 2025
    risk 0.56cvss 8.6epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a server-side request forgery (SSRF) vulnerability. The `/var/www/app/console_release/lexmark/update.php` script is…

  • CVE-2025-34225HigSep 29, 2025
    risk 0.56cvss 8.6epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a server-side request forgery (SSRF) vulnerability. The `console_release` directory is reachable from the internet…

  • CVE-2016-15046HigJul 25, 2025
    risk 0.56cvss —epss 0.01

    A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port 8161). An attacker can exploit this flaw…

  • CVE-2024-41793HigApr 8, 2025
    risk 0.56cvss 8.6epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint that allows to enable the ssh service without authentication. This could allow an unauthenticated remote attacker to enable remote…

  • CVE-2025-21355HigFeb 19, 2025
    risk 0.56cvss 8.6epss 0.02

    Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

  • CVE-2024-12757HigJan 17, 2025
    risk 0.56cvss 8.6epss 0.01

    Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malicious code.

  • CVE-2024-35277HigJan 14, 2025
    risk 0.56cvss 8.6epss 0.01

    A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by…

  • CVE-2024-11980HigNov 29, 2024
    risk 0.56cvss 8.6epss 0.00

    Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.

  • CVE-2024-5721HigNov 22, 2024
    risk 0.56cvss 8.1epss 0.06

    Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this…

  • CVE-2022-45794HigJan 10, 2024
    risk 0.56cvss 8.6epss 0.01

    An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files on the PLC internal memory and memory card.

  • CVE-2023-5376HigJan 9, 2024
    risk 0.56cvss 8.6epss 0.01

    An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

  • CVE-2023-22441HigMay 10, 2023
    risk 0.56cvss 8.6epss 0.01

    Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected…

  • CVE-2023-25014HigFeb 2, 2023
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.

  • CVE-2023-25013HigFeb 2, 2023
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.

  • CVE-2022-32528HigJan 30, 2023
    risk 0.56cvss 8.6epss 0.00

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, potentially leading to a denial-of-service condition when an attacker sends specific messages. …

  • CVE-2021-23858HigOct 4, 2021
    risk 0.56cvss 8.6epss 0.01

    Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware…