VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 313 of 406
  • CVE-2025-46589MedMay 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2025-46588MedMay 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2025-23203MedMar 26, 2025
    risk 0.29cvss 5.5epss 0.00

    Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the…

  • CVE-2025-2546MedMar 20, 2025
    risk 0.29cvss 4.3epss 0.11

    A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The manipulation leads to improper access controls. The attack needs to be…

  • CVE-2024-27200MedNov 13, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-40825MedSep 17, 2024
    risk 0.29cvss 4.4epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with root privileges may be able to modify the contents of system files.

  • CVE-2024-41144MedAug 1, 2024
    risk 0.29cvss 5.5epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled,  which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels

  • CVE-2023-39433MedMay 16, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-20992MedApr 16, 2024
    risk 0.29cvss 4.4epss 0.00

    Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-20036MedMar 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.

  • CVE-2023-43089MedDec 1, 2023
    risk 0.29cvss 4.4epss 0.00

    Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.

  • CVE-2023-44248MedNov 14, 2023
    risk 0.29cvss 4.4epss 0.00

    An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the…

  • CVE-2023-36722MedOct 10, 2023
    risk 0.29cvss 4.4epss 0.01

    Active Directory Domain Services Information Disclosure Vulnerability

  • CVE-2023-43072MedOct 5, 2023
    risk 0.29cvss 4.4epss 0.00

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.

  • CVE-2023-21518MedJun 28, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.

  • CVE-2023-28810MedJun 15, 2023
    risk 0.29cvss 4.3epss 0.10

    Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.

  • CVE-2023-3099MedJun 5, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function delete_file in the library dbus.SystemBus of the component Arbitrary File Handler. The manipulation leads to improper access controls. It is…

  • CVE-2023-23573MedMay 10, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2023-21488MedMay 4, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.

  • CVE-2023-1491MedMar 18, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the library MaxCryptMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is…