VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 26 of 404
  • CVE-2019-15260CriOct 16, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected…

  • CVE-2019-9531CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide…

  • CVE-2019-15068CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.

  • CVE-2019-16377CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.03

    The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.

  • CVE-2019-13656CriSep 6, 2019
    risk 0.64cvss 9.8epss 0.06

    An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.

  • CVE-2018-21007CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.

  • CVE-2017-18543CriAug 16, 2019
    risk 0.64cvss 9.8epss 0.02

    The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.

  • CVE-2019-10938CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All…

  • CVE-2019-9884CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.03

    eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.

  • CVE-2019-10970CriJul 11, 2019
    risk 0.64cvss 9.8epss 0.05

    In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon successful exploit, may…

  • CVE-2019-12468CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.03

    An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

  • CVE-2018-14885CriJun 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.

  • CVE-2018-17148CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.04

    An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

  • CVE-2017-5212CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.

  • CVE-2017-5863CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2019-3927CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.02

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to…

  • CVE-2019-10950CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.04

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access…

  • CVE-2019-0036CriApr 10, 2019
    risk 0.64cvss 9.8epss 0.01

    When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed without error, but the filter criteria will…

  • CVE-2019-6140CriApr 9, 2019
    risk 0.64cvss 9.8epss 0.01

    A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not completed.

  • CVE-2017-7912CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.04

    Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.