VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 145 of 405
  • CVE-2023-3273HigJul 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

  • CVE-2023-35940HigJul 5, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.

  • CVE-2023-3306HigJun 18, 2023
    risk 0.49cvss 7.3epss 0.23

    A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the file app.09df2a9e44ab48766f5f.js of the component Admin Password Handler. The manipulation leads to improper access controls. The…

  • CVE-2023-28809HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and…

  • CVE-2022-39946HigJun 13, 2023
    risk 0.49cvss 7.6epss 0.01

    An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all versions, 8.6 all versions, 8.5 all versions may allow a remote attacker authenticated on the administrative interface to perform…

  • CVE-2023-23446HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

  • CVE-2023-23445HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

  • CVE-2021-23203HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

  • CVE-2021-23178HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

  • CVE-2023-28300HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Azure Service Connector Security Feature Bypass Vulnerability

  • CVE-2023-28877HigMar 31, 2023
    risk 0.49cvss 7.5epss 0.01

    The VTEX [email protected] GraphQL API module does not properly restrict unauthorized access to private configuration data. ([email protected] is unaffected by this issue.)

  • CVE-2023-27875HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.

  • CVE-2023-23911HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.

  • CVE-2023-25605HigMar 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.

  • CVE-2023-22335HigMar 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directory where the product runs. As a result of exploiting this…

  • CVE-2022-47648HigFeb 8, 2023
    risk 0.49cvss 7.6epss 0.00

    An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid…

  • CVE-2023-0451HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including…

  • CVE-2020-22655HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2023-22339HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product.

  • CVE-2023-21893HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for…