VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 189 of 406
  • CVE-2023-28907MedJun 28, 2025
    risk 0.44cvss 6.7epss 0.00

    There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered in Skoda Superb III car…

  • CVE-2025-5382MedJun 5, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.

  • CVE-2024-45371MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-28201MedMay 9, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.

  • CVE-2025-30100MedApr 16, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-29984MedApr 15, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-32726MedApr 12, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24272MedMar 31, 2025
    risk 0.44cvss 6.8epss 0.01

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

  • CVE-2021-22126MedMar 17, 2025
    risk 0.44cvss 6.7epss 0.00

    A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the…

  • CVE-2024-40586MedFeb 11, 2025
    risk 0.44cvss 6.7epss 0.00

    An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.

  • CVE-2024-22067MedNov 18, 2024
    risk 0.44cvss 6.8epss 0.01

    ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.

  • CVE-2024-34022MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-32044MedNov 13, 2024
    risk 0.44cvss 6.8epss 0.00

    Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2024-29077MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some JAM STAPL Player software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-49044MedNov 12, 2024
    risk 0.44cvss 6.7epss 0.01

    Visual Studio Elevation of Privilege Vulnerability

  • CVE-2024-47976MedOct 7, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.

  • CVE-2024-34543MedSep 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-39580MedSep 10, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2024-38223MedAug 13, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Initial Machine Configuration Elevation of Privilege Vulnerability

  • CVE-2024-41905MedAug 13, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive…