VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 208 of 406
  • CVE-2025-37136MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-37135MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-11716MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

  • CVE-2025-20366MedOct 1, 2025
    risk 0.42cvss 6.5epss 0.00

    In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise…

  • CVE-2025-55797MedSep 30, 2025
    risk 0.42cvss 6.5epss 0.00

    An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.

  • CVE-2025-57428MedSep 29, 2025
    risk 0.42cvss 6.5epss 0.00

    Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.

  • CVE-2025-44178MedAug 25, 2025
    risk 0.42cvss 6.5epss 0.00

    DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can exploit this vulnerability to gain unauthorized access to sensitive information and modify its configuration via the UPnP protocol WAN sides without any…

  • CVE-2025-29524MedAug 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in the component /cgi-bin/system_diagnostic_main.asp of DASAN GPON ONU H660WM H660WMR210825 allows attackers to access sensitive information.

  • CVE-2024-46412MedAug 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.

  • CVE-2025-50861MedAug 14, 2025
    risk 0.42cvss 6.5epss 0.00

    The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of…

  • CVE-2025-24323MedAug 12, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-42048MedAug 7, 2025
    risk 0.42cvss 6.5epss 0.00

    OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL…

  • CVE-2025-51054MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint.

  • CVE-2025-46391MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    CWE-284: Improper Access Control

  • CVE-2025-51627MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

  • CVE-2025-51060MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR and WRMSR, respectively. Through this process, the attacker can modify MSR_LSTAR and hook…

  • CVE-2025-43980MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the credentials of root/admin. The GUI doesn't offer a way to disable the account.

  • CVE-2025-53111MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.

  • CVE-2025-52168MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.

  • CVE-2025-52166MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information.