VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 261 of 406
  • CVE-2023-38561MedFeb 14, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25073MedFeb 14, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-22848MedFeb 14, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-40528MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6.4. An app may be able to bypass Privacy preferences.

  • CVE-2024-20969MedJan 16, 2024
    risk 0.36cvss 5.5epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2022-42816MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system.

  • CVE-2023-51384MedDec 18, 2023
    risk 0.36cvss 5.5epss 0.00

    In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns…

  • CVE-2023-50440MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.00

    ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5;…

  • CVE-2023-33872MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control in the Intel Support android application all verions may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-36404MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Information Disclosure Vulnerability

  • CVE-2018-25093MedNov 6, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to…

  • CVE-2018-25092MedNov 5, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version…

  • CVE-2023-25775MedAug 11, 2023
    risk 0.36cvss 5.6epss 0.01

    Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-36889MedAug 8, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Group Policy Security Feature Bypass Vulnerability

  • CVE-2023-24486MedJul 10, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is…

  • CVE-2023-29586MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read by allowing any user to copy any directory in the system to a directory they control. NOTE: the Supplier disputes this because…

  • CVE-2023-25595MedMar 22, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a…

  • CVE-2023-21465MedMar 16, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.

  • CVE-2023-23508MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to bypass Privacy preferences.

  • CVE-2022-32902MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.