VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 170 of 406
  • CVE-2024-13200HigJan 9, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST Request Handler. The manipulation leads…

  • CVE-2024-36488HigNov 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-47910HigOct 4, 2024
    risk 0.47cvss 7.2epss 0.00

    An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

  • CVE-2024-42776HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

  • CVE-2023-31341HigAug 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.

  • CVE-2024-7553HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue…

  • CVE-2024-36537HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.00

    Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2024-36438HigJul 15, 2024
    risk 0.47cvss 7.3epss 0.00

    eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.

  • CVE-2023-40071HigMay 16, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-37341HigMay 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-21110HigApr 16, 2024
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-29055HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    Microsoft Defender for IoT Elevation of Privilege Vulnerability

  • CVE-2024-29054HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    Microsoft Defender for IoT Elevation of Privilege Vulnerability

  • CVE-2024-28405HigMar 29, 2024
    risk 0.47cvss 7.2epss 0.01

    SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.

  • CVE-2023-39244HigFeb 15, 2024
    risk 0.47cvss 7.3epss 0.01

    DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level…

  • CVE-2024-24386HigFeb 15, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

  • CVE-2023-32544HigJan 19, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-46712HigJan 10, 2024
    risk 0.47cvss 7.2epss 0.01

    A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.

  • CVE-2023-39257HigDec 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading…

  • CVE-2023-39256HigDec 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to…