VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 144 of 405
  • CVE-2023-51065HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.

  • CVE-2023-49961HigJan 8, 2024
    risk 0.49cvss 7.5epss 0.00

    WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

  • CVE-2023-50341HigJan 3, 2024
    risk 0.49cvss 7.6epss 0.00

    HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a…

  • CVE-2023-47579HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.

  • CVE-2023-32279HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2023-22285HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2022-36374HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-43901HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.

  • CVE-2023-46759HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2018-17559HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.

  • CVE-2023-46664HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind…

  • CVE-2023-46663HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests.

  • CVE-2023-46662HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access to sensitive information.

  • CVE-2023-38848HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-5240HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

  • CVE-2023-25525HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information…

  • CVE-2023-40850HigSep 13, 2023
    risk 0.49cvss 7.5epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the application security gateway.

  • CVE-2023-36106HigAug 17, 2023
    risk 0.49cvss 7.5epss 0.01

    An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.

  • CVE-2023-25773HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper access control in the Intel(R) Unite(R) Hub software installer for Windows before version 4.2.34962 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-34453HigAug 3, 2023
    risk 0.49cvss 7.6epss 0.00

    Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.