VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 258 of 327
  • CVE-2023-21495MedMay 4, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.

  • CVE-2023-21463MedMar 16, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific…

  • CVE-2023-21447MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

  • CVE-2023-21442MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.

  • CVE-2022-39898MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.

  • CVE-2022-39896MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

  • CVE-2022-39895MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.

  • CVE-2022-39894MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

  • CVE-2022-39889MedNov 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.

  • CVE-2022-39878MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit intent broadcast.

  • CVE-2022-39877MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

  • CVE-2022-39871MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

  • CVE-2022-39870MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.

  • CVE-2022-39869MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.

  • CVE-2022-39868MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

  • CVE-2022-39867MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.

  • CVE-2022-39866MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

  • CVE-2022-39865MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

  • CVE-2022-39851MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.

  • CVE-2022-36866MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.