VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 77 of 150
  • CVE-2025-63896HigDec 4, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.

  • CVE-2025-54851HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to…

  • CVE-2025-54850HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to…

  • CVE-2025-54849HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to…

  • CVE-2025-54848HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to…

  • CVE-2025-34331HigNov 19, 2025
    risk 0.49cvss 7.5epss 0.01

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via the download.php script. The endpoint exposes a file download mechanism that lacks access control, allowing remote, unauthenticated…

  • CVE-2025-59780HigNov 15, 2025
    risk 0.49cvss 7.5epss 0.00

    General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information.

  • CVE-2025-40816HigNov 11, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2)…

  • CVE-2022-50594HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’…

  • CVE-2025-41090HigOct 28, 2025
    risk 0.49cvss epss 0.00

    microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability. This flaw allows an authenticated user to perform unauthorized actions on other organizations' systems by sending direct API requests. To do so, the attacker can use organization identifiers obtained…

  • CVE-2025-61756HigOct 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability…

  • CVE-2025-61752HigOct 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise…

  • CVE-2025-11949HigOct 21, 2025
    risk 0.49cvss 7.5epss 0.00

    EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to obtain database administrator credentials via a specific functionality.

  • CVE-2025-41703HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.

  • CVE-2025-56562HigSep 16, 2025
    risk 0.49cvss 7.5epss 0.00

    An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.

  • CVE-2025-56405HigSep 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.

  • CVE-2025-7970HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.

  • CVE-2023-7308HigAug 27, 2025
    risk 0.49cvss 7.5epss 0.07

    SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The affected component fails to enforce authentication checks on POST requests to retrieve user data. An…

  • CVE-2025-41689HigAug 19, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data.

  • CVE-2025-8754HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.