VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 182 of 406
  • CVE-2023-39349HigAug 7, 2023
    risk 0.46cvss 8.1epss 0.01

    Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with…

  • CVE-2022-40529HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Memory corruption due to improper access control in kernel while processing a mapping request from root process.

  • CVE-2022-41690HigMay 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-31138HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, using object model traversal in the payload of a PATCH request, authenticated users with write…

  • CVE-2023-21980HigApr 18, 2023
    risk 0.46cvss 7.1epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols…

  • CVE-2023-21750HigJan 10, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21531HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.01

    Azure Service Fabric Container Elevation of Privilege Vulnerability

  • CVE-2022-36441HigJan 10, 2023
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other applications that are restricted by the admin.

  • CVE-2022-42327HigNov 1, 2022
    risk 0.46cvss 7.1epss 0.00

    x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared page bypasses the expected isolation that…

  • CVE-2022-3182HigSep 13, 2022
    risk 0.46cvss 7.0epss 0.00

    Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.

  • CVE-2021-3864HigAug 26, 2022
    risk 0.46cvss 7.0epss 0.01

    A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value…

  • CVE-2022-28754HigAug 11, 2022
    risk 0.46cvss 7.1epss 0.01

    Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the…

  • CVE-2022-28753HigAug 11, 2022
    risk 0.46cvss 7.1epss 0.01

    Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the…

  • CVE-2022-33926HigAug 10, 2022
    risk 0.46cvss 7.1epss 0.01

    Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.

  • CVE-2022-28184HigMay 17, 2022
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information…

  • CVE-2021-40414HigJan 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sensitivity of the camera per a range of…

  • CVE-2021-40413HigJan 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version…

  • CVE-2021-27098HigMar 5, 2021
    risk 0.46cvss 8.1epss 0.01

    In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible issuance of an X.509 certificate with a URI SAN for a SPIFFE ID that the agent is…

  • CVE-2019-18998HigFeb 17, 2020
    risk 0.46cvss 7.1epss 0.01

    Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

  • CVE-2019-10964HigJun 28, 2019
    risk 0.46cvss 7.1epss 0.01

    Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or…