VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 22 of 404
  • CVE-2024-41912CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.

  • CVE-2024-38909CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

  • CVE-2024-40117CriJul 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway…

  • CVE-2024-36535CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2024-39376CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.00

    TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.

  • CVE-2024-21741CriJun 25, 2024
    risk 0.64cvss 9.8epss 0.00

    GigaDevice GD32E103C8T6 devices have Incorrect Access Control.

  • CVE-2024-33898CriJun 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.

  • CVE-2024-22074CriJun 6, 2024
    risk 0.64cvss 9.8epss 0.00

    Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. This is fixed in 1.8.2014, 1.7.4212, 1.6.3212, 1.5.31212, 1.4.3212,…

  • CVE-2024-35396CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.

  • CVE-2024-5168CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.

  • CVE-2024-36080CriMay 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

  • CVE-2023-49473CriApr 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorrect Access Control.

  • CVE-2024-32418CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

  • CVE-2024-29836CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.

  • CVE-2024-3765CriApr 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality of the component Sofia Service. The manipulation…

  • CVE-2022-47036CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in…

  • CVE-2024-28390CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.

  • CVE-2022-32257CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to…

  • CVE-2023-38945CriMar 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass the access control and gain complete access to the application via supplying a crafted URL.

  • CVE-2023-49543CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.