VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 295 of 406
  • CVE-2024-39285MedNov 13, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2019-20462MedNov 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password…

  • CVE-2024-48932MedOct 24, 2024
    risk 0.34cvss 5.3epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http:///v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization.…

  • CVE-2024-21248MedOct 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2024-45124MedOct 10, 2024
    risk 0.34cvss 5.3epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have a low impact on…

  • CVE-2024-9321MedSep 29, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper access controls. The…

  • CVE-2024-37993MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT…

  • CVE-2024-42022MedSep 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

  • CVE-2023-30582MedSep 7, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file watching through the…

  • CVE-2024-5814MedAug 27, 2024
    risk 0.34cvss 5.3epss 0.00

    A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. …

  • CVE-2024-41250MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.

  • CVE-2024-41245MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.

  • CVE-2024-41244MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.

  • CVE-2024-41243MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.

  • CVE-2024-41248MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.

  • CVE-2024-41247MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.

  • CVE-2024-41246MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.

  • CVE-2024-6738MedJul 15, 2024
    risk 0.34cvss 5.3epss 0.00

    The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.

  • CVE-2024-39701MedJul 8, 2024
    risk 0.34cvss 6.3epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} would evaluate to true…

  • CVE-2024-6428MedJul 3, 2024
    risk 0.34cvss 5.3epss 0.00

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause…