VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 139 of 405
  • CVE-2025-37125HigSep 16, 2025
    risk 0.49cvss 7.5epss 0.00

    A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

  • CVE-2025-24088HigSep 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.

  • CVE-2025-45584HigSep 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication.

  • CVE-2024-45432HigSep 12, 2025
    risk 0.49cvss 7.5epss 0.01

    OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain…

  • CVE-2025-56406HigSep 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended…

  • CVE-2025-56405HigSep 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.

  • CVE-2025-55238HigSep 4, 2025
    risk 0.49cvss 7.5epss 0.01

    Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

  • CVE-2025-54599HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an…

  • CVE-2025-29421HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.

  • CVE-2024-53494HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.

  • CVE-2024-57152HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class

  • CVE-2024-53495HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

  • CVE-2025-51532HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

  • CVE-2025-33056HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

  • CVE-2025-20100HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-31247HigMay 12, 2025
    risk 0.49cvss 7.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system.

  • CVE-2025-45617HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45614HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45613HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45610HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.