VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 249 of 406
  • CVE-2021-45730MedMay 19, 2022
    risk 0.39cvss 6.0epss 0.01

    JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

  • CVE-2021-43986MedApr 20, 2022
    risk 0.39cvss 6.0epss 0.00

    The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.

  • CVE-2022-0580HigFeb 14, 2022
    risk 0.39cvss 7.1epss 0.01

    Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

  • CVE-2021-34724MedSep 23, 2021
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 user.…

  • CVE-2020-3503MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device.…

  • CVE-2016-1587HigApr 22, 2019
    risk 0.39cvss 7.1epss 0.01

    The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package,…

  • CVE-2016-6543MedJul 13, 2018
    risk 0.39cvss 5.9epss 0.02

    A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.

  • CVE-2015-5293MedAug 24, 2017
    risk 0.39cvss 5.9epss 0.02

    Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.

  • CVE-2015-7898MedJun 27, 2017
    risk 0.39cvss 5.5epss 0.01

    Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

  • CVE-2015-7895MedJun 27, 2017
    risk 0.39cvss 5.5epss 0.01

    Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

  • CVE-2016-4081MedApr 25, 2016
    risk 0.39cvss 5.9epss 0.02

    epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

  • CVE-2026-20120MedSep 16, 2026
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass…

  • CVE-2026-80438MedSep 4, 2026
    risk 0.38cvss 5.9epss 0.00

    The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read…

  • CVE-2026-51756MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51748MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51742MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51739MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51714MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51712MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-55678MedAug 28, 2026
    risk 0.38cvss —epss 0.01

    Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not configured. The defaults in…