VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 192 of 406
  • CVE-2023-22232MedFeb 17, 2023
    risk 0.44cvss 5.3epss 0.83

    Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of…

  • CVE-2022-46677MedFeb 11, 2023
    risk 0.44cvss 6.8epss 0.01

    Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.

  • CVE-2022-25627MedDec 16, 2022
    risk 0.44cvss 6.7epss 0.01

    An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4

  • CVE-2022-36385MedSep 13, 2022
    risk 0.44cvss 6.8epss 0.00

    A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware…

  • CVE-2022-2088MedJun 27, 2022
    risk 0.44cvss 6.8epss 0.01

    An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0.

  • CVE-2020-25160MedApr 14, 2022
    risk 0.44cvss 6.8epss 0.00

    Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.

  • CVE-2022-28542MedApr 11, 2022
    risk 0.44cvss 6.8epss 0.00

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.

  • CVE-2022-24731MedMar 23, 2022
    risk 0.44cvss 6.8epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal vulnerability, allowing a malicious user with read/write access to leak sensitive files…

  • CVE-2022-24309MedMar 8, 2022
    risk 0.44cvss 6.8epss 0.01

    A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (All versions < V9.13 only with Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to False). If an entity has an…

  • CVE-2021-34402MedJan 18, 2022
    risk 0.44cvss 6.7epss 0.00

    NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss…

  • CVE-2021-1449MedMar 24, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An…

  • CVE-2019-20473MedFeb 1, 2021
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for…

  • CVE-2020-16261MedOct 28, 2020
    risk 0.44cvss 6.8epss 0.00

    Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.

  • CVE-2020-3524MedSep 24, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation Services Routers, Cisco ASR 1000 Series Aggregation Services Routers, and Cisco cBR-8 Converged Broadband Routers could allow an…

  • CVE-2020-3396MedSep 24, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections.…

  • CVE-2020-3253MedMay 6, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the…

  • CVE-2020-8157MedMay 2, 2020
    risk 0.44cvss 6.8epss 0.00

    UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).

  • CVE-2019-15999MedJan 6, 2020
    risk 0.44cvss 6.3epss 0.04

    A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an…

  • CVE-2019-12670MedSep 25, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device. The vulnerability is due to insufficient file permissions. An attacker could…

  • CVE-2019-1622MedJun 27, 2019
    risk 0.44cvss 5.3epss 0.79

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on…