VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 24 of 404
  • CVE-2023-29924CriApr 21, 2023
    risk 0.64cvss 9.8epss 0.01

    PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.

  • CVE-2023-29526CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display macros. A comment with either…

  • CVE-2023-28531CriMar 17, 2023
    risk 0.64cvss 9.8epss 0.02

    ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

  • CVE-2023-24468CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2

  • CVE-2023-26474CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.

  • CVE-2023-24320CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2023-22920CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet.

  • CVE-2023-22807CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.

  • CVE-2022-46892CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.

  • CVE-2022-47699CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.

  • CVE-2022-43977CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.

  • CVE-2022-45778CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.01

    https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator…

  • CVE-2022-39070CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

  • CVE-2022-34827CriNov 18, 2022
    risk 0.64cvss 9.9epss 0.01

    Carel Boss Mini 1.5.0 has Improper Access Control.

  • CVE-2022-31687CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

  • CVE-2021-46851CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.

  • CVE-2022-25932CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.

  • CVE-2022-27805CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted network request can lead to arbitrary XCMD execution. An attacker can send a malicious XML payload to trigger…

  • CVE-2022-2052CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

  • CVE-2022-27178CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A denial of service vulnerability exists in the confctl_set_wan_cfg functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.