VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 149 of 405
  • CVE-2019-12627HigAug 21, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to insufficient application identification.…

  • CVE-2019-5036HigAug 20, 2019
    risk 0.49cvss 7.5epss 0.00

    An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker…

  • CVE-2015-9291HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

  • CVE-2017-18380HigJul 30, 2019
    risk 0.49cvss 7.5epss 0.01

    edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.

  • CVE-2019-9886HigJul 11, 2019
    risk 0.49cvss 7.5epss 0.02

    Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.

  • CVE-2019-12472HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.01

    An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2018-10691HigJun 7, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.

  • CVE-2019-3936HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.02

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition into a "stopped" state. A remote, unauthenticated attacker can use this…

  • CVE-2019-6554HigApr 5, 2019
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

  • CVE-2019-1763HigMar 22, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition.…

  • CVE-2019-6520HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.02

    Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.

  • CVE-2018-19634HigJan 22, 2019
    risk 0.49cvss 7.5epss 0.01

    CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

  • CVE-2018-17953HigNov 27, 2018
    risk 0.49cvss 7.5epss 0.01

    A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).

  • CVE-2018-7362HigNov 16, 2018
    risk 0.49cvss 7.5epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.

  • CVE-2013-2972HigJul 11, 2018
    risk 0.49cvss 7.5epss 0.02

    IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868.

  • CVE-2018-1080HigJul 3, 2018
    risk 0.49cvss 7.5epss 0.02

    Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny),…

  • CVE-2016-10418HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, and SD 835, HLOS can enable PMIC debug…

  • CVE-2015-9140HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 600, SD…

  • CVE-2015-5350HigMar 19, 2018
    risk 0.49cvss 7.5epss 0.01

    In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end…

  • CVE-2014-9504HigFeb 1, 2018
    risk 0.49cvss 7.5epss 0.02

    The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.