VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 291 of 406
  • CVE-2025-43308MedSep 15, 2025
    risk 0.34cvss 5.3epss 0.00

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access sensitive user data.

  • CVE-2025-10321MedSep 12, 2025
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been published and may be used. The vendor was…

  • CVE-2025-20159MedSep 10, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This vulnerability exists because management…

  • CVE-2025-36909MedSep 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Information disclosure

  • CVE-2025-20335MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to a lack of…

  • CVE-2025-9843MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information disclosure. It is possible to initiate the attack remotely. The exploit has been published and…

  • CVE-2025-9842MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information disclosure. The attack may be performed from remote. The exploit is now public and…

  • CVE-2025-55373MedSep 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privileges and execute commands with Administrator rights.

  • CVE-2025-57219MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request.

  • CVE-2025-29520MedAug 25, 2025
    risk 0.34cvss 5.3epss 0.01

    Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account passwords and escalate privileges.

  • CVE-2025-9398MedAug 25, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file app/utils/base/database/Migrate.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The…

  • CVE-2025-55626MedAug 22, 2025
    risk 0.34cvss 5.3epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to access the Admin-only settings and edit the session storage.

  • CVE-2025-55371MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.

  • CVE-2025-55367MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

  • CVE-2025-55366MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.

  • CVE-2025-50434MedAug 19, 2025
    risk 0.34cvss 5.3epss 0.00

    A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrect access control, which under certain conditions could allow unauthorized access to information. NOTE: this has been disputed because the…

  • CVE-2025-51529MedAug 19, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unlimited database write operations to the…

  • CVE-2025-20219MedAug 14, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that…

  • CVE-2025-48861MedAug 14, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to access and extract internal application data, including potential debug logs and the version of installed apps.

  • CVE-2025-8738MedAug 8, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The manipulation leads to information disclosure. The attack can…