BaseDraftTop 25 #25

CWE-306Missing Authentication for Critical Function

Category: auth

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Common consequences· 1

  • Access Control / Other — Gain Privileges or Assume Identity, Varies by Context
    Exposing critical functionality essentially provides an attacker with the privilege level of that functionality. The consequences will depend on the associated functionality, but they can range from reading or modifying sensitive data, accessing administrative or other privileged functionality, or possibly even executing arbitrary code.

Potential mitigations· 5

  • [Architecture and Design]
  • [Architecture and Design]For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
  • [Architecture and Design]
  • [Architecture and Design]
  • [Implementation, System Configuration, Operation]When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to require strong authentication for users who should be allowed to access the data [REF-1297] [REF-1298] [REF-1302].

Related CAPEC attack patterns· 5

CAPEC-12CAPEC-166CAPEC-216CAPEC-36CAPEC-62

References

  1. https://cwe.mitre.org/data/definitions/306.html

Exploits (incoming)4

TypeTargetConfidenceTier
AttackPatternUsing Unpublished Interfaces or Functionalitycapec-36100%live
AttackPatternCommunication Channel Manipulationcapec-216100%live
AttackPatternChoosing Message Identifiercapec-12100%live
AttackPatternCross Site Request Forgerycapec-62100%live

Compliance frameworks addressing this (incoming)34

TypeTargetConfidenceTier
ComplianceControliso27701-a.7.3.1100%live
ComplianceControliso27701-a.7.2.1100%live
ComplianceControldora-art13100%live
ComplianceControliso27001-a.8.2100%live
ComplianceControldora-art5100%live
ComplianceControlnist_csf-id100%live
ComplianceControlowasp_top10-a01100%live
ComplianceControldora-art10100%live
ComplianceControlcis_v8-7100%live
ComplianceControlnist_csf-rs100%live
ComplianceControliso27701-a.7.3.6100%live
ComplianceControlpci_dss_v4-r8100%live
ComplianceControltiber_eu-generic100%live
ComplianceControlcis_v8-5100%live
ComplianceControlpci_dss_v4-r12100%live
ComplianceControliso27001-a.8.25100%live
ComplianceControlowasp_llm_top10-llm08100%live
ComplianceControlpci_dss_v4-r1100%live
ComplianceControldora-art7100%live
ComplianceControliso27001-a.8.5100%live
ComplianceControlowasp_api_top10-api09100%live
ComplianceControldora-art11100%live
ComplianceControlai_act-art73100%live
ComplianceControlnist_csf-de100%live
ComplianceControlnis2-art21j100%live
ComplianceControlnist_csf-gv100%live
ComplianceControlpci_dss_v4-r9100%live
ComplianceControlnis2-art21g100%live
ComplianceControldora-art9100%live
ComplianceControlcra-annexi-2100%live

Showing top 30 of 34 by confidence. Click any target to see the full neighbourhood.

(incoming)112

TypeTargetConfidenceTier
VulnerabilityPalo Alto Networks PAN-OS Authentication Bypass Vulnerabilitycve-2025-01080%live
VulnerabilityCVE-2025-0159cve-2025-01590%live
VulnerabilityCVE-2025-0456cve-2025-04560%live
VulnerabilityCVE-2025-0896cve-2025-08960%live
VulnerabilityCVE-2025-10452cve-2025-104520%live
VulnerabilityCVE-2025-10906cve-2025-109060%live
VulnerabilityCVE-2025-11007cve-2025-110070%live
VulnerabilityCVE-2025-11130cve-2025-111300%live
VulnerabilityCVE-2025-11529cve-2025-115290%live
VulnerabilityCVE-2025-11661cve-2025-116610%live
VulnerabilityCVE-2025-11942cve-2025-119420%live
VulnerabilityCVE-2025-12049cve-2025-120490%live
VulnerabilityCVE-2025-12476cve-2025-124760%live
VulnerabilityCVE-2025-12477cve-2025-124770%live
VulnerabilityCVE-2025-12548cve-2025-125480%live
VulnerabilityCVE-2025-1283cve-2025-12830%live
VulnerabilityCVE-2025-13030cve-2025-130300%live
VulnerabilityCVE-2025-1315cve-2025-13150%live
VulnerabilityCVE-2025-13607cve-2025-136070%live
VulnerabilityCVE-2025-13779cve-2025-137790%live
VulnerabilityCVE-2025-14300cve-2025-143000%live
VulnerabilityCVE-2025-14346cve-2025-143460%live
VulnerabilityCVE-2025-14349cve-2025-143490%live
VulnerabilityCVE-2025-14577cve-2025-145770%live
VulnerabilityCVE-2025-15026cve-2025-150260%live
VulnerabilityCVE-2025-15517cve-2025-155170%live
VulnerabilityCVE-2025-15620cve-2025-156200%live
VulnerabilityCVE-2025-1717cve-2025-17170%live
VulnerabilityCVE-2025-1907cve-2025-19070%live
VulnerabilityCVE-2025-20358cve-2025-203580%live

Showing top 30 of 112 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Weak Authentication
CWE
Missing Authorization
CWE
Missing Encryption of Sensitive Data
CWE
Improper Access Control
CWE
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CWE
Insufficiently Protected Credentials
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.