243 – Authentication mechanism absence or evasion - Admin Console
Description
Some functions of the application can be accessed without having to be logged into the server. Some only allow you to view and others, to edit some values.
Impact
- List confidential information in the application. - Edit information in the application.
Recommendation
Protect resources that are not authenticated for access.
Threat
Unauthorized user from internal network.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: A
- Attack complexity: L
- Attack Requirements: N
- Privileges required: N
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X