VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 23 of 404
  • CVE-2023-49931CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

  • CVE-2023-49930CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.

  • CVE-2022-34270CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

  • CVE-2024-25169CriFeb 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

  • CVE-2024-24300CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.

  • CVE-2024-21401CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

  • CVE-2024-24830CriFeb 8, 2024
    risk 0.64cvss 9.9epss 0.01

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to…

  • CVE-2024-0642CriJan 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.

  • CVE-2023-46665CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

  • CVE-2023-46661CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

  • CVE-2023-42769CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

  • CVE-2023-43119CriOct 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.

  • CVE-2023-24479CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-5365CriOct 9, 2023
    risk 0.64cvss 9.8epss 0.01

    HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.

  • CVE-2023-5288CriSep 29, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

  • CVE-2023-43141CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

  • CVE-2023-40039CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

  • CVE-2023-29130CriJul 11, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete…

  • CVE-2021-4380CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for…

  • CVE-2021-4360CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted…