VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,339)

page 74 of 167
  • CVE-2025-3090HigJun 24, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

  • CVE-2025-3319HigJun 20, 2025
    risk 0.53cvss 8.1epss 0.00

    IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result in access to unauthorized resources.

  • CVE-2025-41654HigMay 26, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog.

  • CVE-2025-25060HigApr 2, 2025
    risk 0.53cvss 8.2epss 0.01

    Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.

  • CVE-2024-8053HigMar 20, 2025
    risk 0.53cvss 8.2epss 0.01

    In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload,…

  • CVE-2024-10776HigDec 6, 2024
    risk 0.53cvss 8.2epss 0.01

    Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.

  • CVE-2024-49052HigNov 26, 2024
    risk 0.53cvss 8.2epss 0.01

    Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2024-5718HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.01

    Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this…

  • CVE-2024-41967HigNov 18, 2024
    risk 0.53cvss 8.1epss 0.00

    A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

  • CVE-2024-40405HigNov 13, 2024
    risk 0.53cvss 8.1epss 0.00

    Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.

  • CVE-2024-47912HigOct 21, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missing authentication mechanisms. A successful exploit could…

  • CVE-2024-7628HigAug 15, 2024
    risk 0.53cvss 8.1epss 0.01

    The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for…

  • CVE-2024-21146HigJul 16, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-36470HigMay 29, 2024
    risk 0.53cvss 8.1epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

  • CVE-2022-34321HigMar 12, 2024
    risk 0.53cvss 8.2epss 0.02

    Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of…

  • CVE-2023-5881HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.01

    Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's SSID settings.

  • CVE-2023-26573HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

  • CVE-2023-22101HigOct 17, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-34392HigAug 31, 2023
    risk 0.53cvss 8.2epss 0.00

    A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A…

  • CVE-2023-36847MedKEVAug 17, 2023
    risk 0.53cvss 5.3epss 0.83

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't…