VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 191 of 406
  • CVE-2023-44282MedNov 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.

  • CVE-2023-27879MedNov 14, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.

  • CVE-2022-38786MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-45844MedOct 25, 2023
    risk 0.44cvss 6.8epss 0.00

    The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the device power management or eventually the device secure…

  • CVE-2023-46033MedOct 19, 2023
    risk 0.44cvss 6.8epss 0.00

    D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.

  • CVE-2023-37194MedOct 10, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is exposed to user-mode via direct memory…

  • CVE-2023-1832MedOct 4, 2023
    risk 0.44cvss 6.8epss 0.01

    An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

  • CVE-2023-34470MedSep 12, 2023
    risk 0.44cvss 6.8epss 0.00

    AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability.

  • CVE-2022-3746MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.

  • CVE-2023-4107MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.01

    Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.

  • CVE-2023-27391MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-29871MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-29242MedMay 12, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-40972MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-32578MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-21493MedMay 4, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.

  • CVE-2023-28070MedMay 3, 2023
    risk 0.44cvss 6.7epss 0.00

    Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A local malicious user could potentially exploit this vulnerability during installation or update process leading to privilege escalation.

  • CVE-2023-21969MedApr 18, 2023
    risk 0.44cvss 6.7epss 0.00

    Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL Developer executes to compromise Oracle…

  • CVE-2023-21922MedApr 18, 2023
    risk 0.44cvss 6.8epss 0.00

    Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network…

  • CVE-2023-0916MedFeb 19, 2023
    risk 0.44cvss 6.3epss 0.03

    A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched…