VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 252 of 406
  • CVE-2024-20291MedFeb 29, 2024
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. …

  • CVE-2024-20263MedJan 26, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured…

  • CVE-2024-20926MedJan 16, 2024
    risk 0.38cvss 5.9epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM…

  • CVE-2023-32065MedNov 28, 2023
    risk 0.38cvss 5.8epss 0.00

    OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.

  • CVE-2023-22448MedNov 14, 2023
    risk 0.38cvss 5.9epss 0.01

    Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2023-20191MedSep 13, 2023
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incomplete support for this feature. An…

  • CVE-2023-25771MedMay 10, 2023
    risk 0.38cvss 5.8epss 0.00

    Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2023-0319MedApr 5, 2023
    risk 0.38cvss 5.8epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

  • CVE-2023-23835MedFeb 14, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All…

  • CVE-2022-44212MedDec 1, 2022
    risk 0.38cvss 5.9epss 0.01

    In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.

  • CVE-2022-36867MedSep 9, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.

  • CVE-2021-28511MedAug 5, 2022
    risk 0.38cvss 5.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could…

  • CVE-2022-1261MedMay 26, 2022
    risk 0.38cvss 5.8epss 0.01

    Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-level privileges.

  • CVE-2021-34754MedOct 27, 2021
    risk 0.38cvss 5.8epss 0.01

    Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to…

  • CVE-2021-34696MedSep 23, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is…

  • CVE-2021-1625MedSep 23, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP responder-to-initiator…

  • CVE-2021-1591MedAug 25, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to oversubscription of…

  • CVE-2020-14312MedFeb 6, 2021
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option…

  • CVE-2021-1389MedFeb 4, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for an interface of an affected device. The…

  • CVE-2021-0205MedJan 15, 2021
    risk 0.38cvss 5.8epss 0.01

    When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to block unexpected traffic. This issue affects…