VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 190 of 406
  • CVE-2024-21302MedAug 8, 2024
    risk 0.44cvss 6.7epss 0.02

    Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your…

  • CVE-2024-39934HigJul 4, 2024
    risk 0.44cvss 7.8epss 0.00

    Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.

  • CVE-2024-5430MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

  • CVE-2024-29060MedJun 11, 2024
    risk 0.44cvss 6.7epss 0.01

    Visual Studio Elevation of Privilege Vulnerability

  • CVE-2024-22026MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

  • CVE-2024-21828MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-34404MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a…

  • CVE-2024-21107MedApr 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-24487MedApr 15, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command.

  • CVE-2024-26234MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.05

    Proxy Driver Spoofing Vulnerability

  • CVE-2024-22459MedFeb 28, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and…

  • CVE-2023-39432MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32647MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.00

    Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-31271MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25174MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22311MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32479MedFeb 6, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this…

  • CVE-2023-51751MedJan 11, 2024
    risk 0.44cvss 6.8epss 0.00

    ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

  • CVE-2023-44292MedNov 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.

  • CVE-2023-44282MedNov 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.