VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 148 of 405
  • CVE-2021-20050HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.

  • CVE-2021-42360HigNov 17, 2021
    risk 0.49cvss 7.6epss 0.01

    On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft…

  • CVE-2021-26338HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.

  • CVE-2021-42359HigNov 5, 2021
    risk 0.49cvss 7.5epss 0.04

    WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for…

  • CVE-2021-32517HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular parameter in download function. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-32514HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-21083HigJun 28, 2021
    risk 0.49cvss 7.5epss 0.02

    AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service in…

  • CVE-2020-7038HigApr 28, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected versions of Management component of Avaya Equinox…

  • CVE-2019-20470HigFeb 1, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated by sending a specific SMS and using the…

  • CVE-2020-10937HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputation system to poison other nodes' routing tables, eclipsing the nodes that are the target of the attack from the rest…

  • CVE-2020-14499HigJul 15, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

  • CVE-2020-3312HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application…

  • CVE-2020-10641HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a…

  • CVE-2019-3942HigApr 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

  • CVE-2019-6193HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.

  • CVE-2019-12999HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.

  • CVE-2019-15590HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

  • CVE-2020-3142HigJan 26, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile…

  • CVE-2019-11899HigSep 12, 2019
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch Access Professional Edition (APE) 3.8, client installations need to be authorized by the APE administrator.

  • CVE-2015-9337HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.