CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,080)
page 23 of 404| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49931 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted. | ||
| CVE-2023-49930 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. | ||
| CVE-2022-34270 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager. | ||
| CVE-2024-25169 | Cri | 0.64 | 9.8 | 0.01 | Feb 28, 2024 | An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request. | ||
| CVE-2024-24300 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged. | ||
| CVE-2024-21401 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | ||
| CVE-2024-24830 | Cri | 0.64 | 9.9 | 0.01 | Feb 8, 2024 | OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to… | ||
| CVE-2024-0642 | Cri | 0.64 | 9.8 | 0.01 | Jan 17, 2024 | Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management. | ||
| CVE-2023-46665 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2023 | Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges. | ||
| CVE-2023-46661 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2023 | Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests. | ||
| CVE-2023-42769 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2023 | The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter. | ||
| CVE-2023-43119 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2023 | An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server. | ||
| CVE-2023-24479 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2023 | An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-5365 | Cri | 0.64 | 9.8 | 0.01 | Oct 9, 2023 | HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure. | ||
| CVE-2023-5288 | Cri | 0.64 | 9.8 | 0.01 | Sep 29, 2023 | A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device. | ||
| CVE-2023-43141 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. | ||
| CVE-2023-40039 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. | ||
| CVE-2023-29130 | Cri | 0.64 | 9.9 | 0.01 | Jul 11, 2023 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete… | ||
| CVE-2021-4380 | Cri | 0.64 | 9.8 | 0.04 | Jun 7, 2023 | The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for… | ||
| CVE-2021-4360 | Cri | 0.64 | 9.9 | 0.01 | Jun 7, 2023 | The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted… |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
- risk 0.64cvss 9.8epss 0.01
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.
- risk 0.64cvss 9.8epss 0.01
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.
- risk 0.64cvss 9.8epss 0.01
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
- risk 0.64cvss 9.9epss 0.01
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to…
- risk 0.64cvss 9.8epss 0.01
Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.
- risk 0.64cvss 9.8epss 0.01
Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.
- risk 0.64cvss 9.8epss 0.01
Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.
- risk 0.64cvss 9.8epss 0.01
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
- risk 0.64cvss 9.8epss 0.01
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
- risk 0.64cvss 9.8epss 0.02
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
- risk 0.64cvss 9.8epss 0.01
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.
- risk 0.64cvss 9.9epss 0.01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete…
- risk 0.64cvss 9.8epss 0.04
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for…
- risk 0.64cvss 9.9epss 0.01
The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted…