CWE-306: No Authentication for Critical Function
No Authentication for Critical Function
Weakness ID: 306 (Weakness Variant) Status: Draft
Description
Description Summary
The software does not perform any authentication for
functionality that requires a provable user identity or consumes a significant
amount of resources.
Time of Introduction
Observed Examples
Reference Description
CVE-2002-1810 MFV. Access TFTP server without authentication and
obtain configuration file with sensitive plaintext
information.
Relationships
Nature Type ID Name View(s) this relationship pertains to
ChildOf Weakness Class 287 Improper Authentication Development Concepts (primary) 699
Research Concepts (primary) 1000
Relationship Notes
This is separate from "bypass" issues in which authentication exists, but
is faulty.
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER No Authentication for Critical Function
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time of Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships, Relationship Notes,
Taxonomy Mappings