VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 209 of 406
  • CVE-2025-45157MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

  • CVE-2025-50071MedJul 15, 2025
    risk 0.42cvss 6.4epss 0.00

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2025-44525MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted…

  • CVE-2025-44526MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.

  • CVE-2025-50405MedJul 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation function.

  • CVE-2025-31698HigJun 19, 2025
    risk 0.42cvss 7.5epss 0.01

    ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY…

  • CVE-2025-27207MedJun 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and…

  • CVE-2024-57336MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.

  • CVE-2025-5257MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensitive information. …

  • CVE-2025-28371MedMay 19, 2025
    risk 0.42cvss 6.5epss 0.00

    EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.

  • CVE-2024-6364MedMay 13, 2025
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability,…

  • CVE-2025-31258MedMay 12, 2025
    risk 0.42cvss 6.5epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

  • CVE-2025-20190MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of…

  • CVE-2025-29448HigMay 7, 2025
    risk 0.42cvss 7.5epss 0.01

    Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.

  • CVE-2025-45618MedMay 5, 2025
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-4269MedMay 5, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with the input…

  • CVE-2025-46629MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet

  • CVE-2025-28367MedApr 21, 2025
    risk 0.42cvss 6.5epss 0.02

    mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.

  • CVE-2024-53304MedApr 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as an infected machine.

  • CVE-2025-30740MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD…