VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 143 of 405
  • CVE-2024-29841HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user

  • CVE-2024-29840HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user

  • CVE-2024-29839HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user

  • CVE-2024-1308HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated…

  • CVE-2024-27895HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-52537HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-30418HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-36644HigApr 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.

  • CVE-2023-36643HigApr 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.

  • CVE-2024-27605HigApr 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.

  • CVE-2022-47037HigMar 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

  • CVE-2023-49545HigMar 1, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2023-52375HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-44031HigFeb 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request.

  • CVE-2023-47034HigJan 19, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.

  • CVE-2024-20932HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition:…

  • CVE-2023-52105HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-52099HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52114HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2023-51070HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.