VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 171 of 406
  • CVE-2023-44290HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation.

  • CVE-2023-44289HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation.

  • CVE-2023-43086HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modify files inside installation folder during application upgrade, leading to privilege escalation.

  • CVE-2023-39253HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system.

  • CVE-2023-5299HigNov 22, 2023
    risk 0.47cvss 7.3epss 0.00

    A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.

  • CVE-2023-39259HigNov 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system.

  • CVE-2022-41689HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-43079HigOct 13, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the…

  • CVE-2023-32458HigSep 27, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege…

  • CVE-2023-3039HigSep 12, 2023
    risk 0.47cvss 7.3epss 0.00

    SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.

  • CVE-2023-40060HigSep 7, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  SolarWinds found that the…

  • CVE-2021-36036HigSep 6, 2023
    risk 0.47cvss 7.2epss 0.02

    Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker…

  • CVE-2023-25757HigAug 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) Unison(TM) software before version 10.12 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2022-45112HigAug 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-37343HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-35179HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 

  • CVE-2023-38167HigAug 8, 2023
    risk 0.47cvss 7.2epss 0.01

    Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

  • CVE-2023-28066HigJun 1, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability in order to elevate privileges on the system.

  • CVE-2023-22312HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-42465HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access.