VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 195 of 406
  • CVE-2025-46362MedNov 13, 2025
    risk 0.43cvss 6.6epss 0.00

    Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

  • CVE-2025-4962HigAug 18, 2025
    risk 0.43cvss 7.7epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the `projectId`…

  • CVE-2025-20242MedMay 21, 2025
    risk 0.43cvss 6.5epss 0.06

    A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker…

  • CVE-2025-24198MedMar 31, 2025
    risk 0.43cvss 6.6epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive…

  • CVE-2025-21105MedFeb 20, 2025
    risk 0.43cvss 6.6epss 0.00

    Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administrative action permitted by it resulting…

  • CVE-2024-24902MedDec 13, 2024
    risk 0.43cvss 6.6epss 0.00

    Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.

  • CVE-2024-26201MedMar 12, 2024
    risk 0.43cvss 6.6epss 0.01

    Microsoft Intune Linux Agent Elevation of Privilege Vulnerability

  • CVE-2023-40161MedFeb 14, 2024
    risk 0.43cvss 6.6epss 0.00

    Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27517MedFeb 14, 2024
    risk 0.43cvss 6.6epss 0.00

    Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27509MedAug 11, 2023
    risk 0.43cvss 6.6epss 0.00

    Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user to potentially enable escalation of privileges via local access.

  • CVE-2023-22487HigJan 11, 2023
    risk 0.43cvss 7.7epss 0.01

    Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extension, users can mention any post ID on the forum with the special `@""#p` syntax. The following behavior never changes no matter if the actor should…

  • CVE-2022-1959MedSep 30, 2022
    risk 0.43cvss 6.6epss 0.00

    AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the application did not correctly implement fingerprint validations.

  • CVE-2022-36875MedSep 9, 2022
    risk 0.43cvss 6.6epss 0.00

    Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.

  • CVE-2022-36869MedSep 9, 2022
    risk 0.43cvss 6.6epss 0.00

    Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.

  • CVE-2022-2792MedAug 19, 2022
    risk 0.43cvss 6.6epss 0.00

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.

  • CVE-2022-27822MedApr 11, 2022
    risk 0.43cvss 6.6epss 0.00

    Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

  • CVE-2022-23134LowKEVJan 13, 2022
    risk 0.43cvss 3.7epss 0.95

    After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

  • CVE-2021-27653MedApr 1, 2021
    risk 0.43cvss 6.6epss 0.01

    Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

  • CVE-2020-1666MedOct 16, 2020
    risk 0.43cvss 6.6epss 0.00

    The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ability to resume a…

  • CVE-2017-12171MedJul 26, 2018
    risk 0.43cvss 6.5epss 0.08

    A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.