VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 43 of 405
  • CVE-2025-54391CriSep 16, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party…

  • CVE-2025-55244CriSep 4, 2025
    risk 0.59cvss 9.0epss 0.01

    Azure Bot Service Elevation of Privilege Vulnerability

  • CVE-2024-45438CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a…

  • CVE-2025-49603CriJun 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

  • CVE-2025-44619CriMay 30, 2025
    risk 0.59cvss 9.1epss 0.00

    Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.

  • CVE-2025-30436CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.

  • CVE-2024-48905CriMay 1, 2025
    risk 0.59cvss 9.1epss 0.00

    Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

  • CVE-2025-28104CriApr 21, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

  • CVE-2025-28233CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to…

  • CVE-2025-28231CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.

  • CVE-2025-28232CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

  • CVE-2025-3113CriApr 17, 2025
    risk 0.59cvss —epss 0.00

    A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the application’s built-in Connector functionality to access Continuous Compliance’s internal database. This allows the user to…

  • CVE-2025-22940CriMar 31, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

  • CVE-2025-30132CriMar 18, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. During analysis, it was found that this domain was not owned by IROAD, allowing an attacker to register it and potentially intercept…

  • CVE-2025-1260CriMar 4, 2025
    risk 0.59cvss 9.1epss 0.00

    On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.

  • CVE-2025-1941CriMar 4, 2025
    risk 0.59cvss 9.1epss 0.00

    Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.

  • CVE-2024-37567CriFeb 27, 2025
    risk 0.59cvss 9.1epss 0.00

    Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.

  • CVE-2020-35546CriFeb 19, 2025
    risk 0.59cvss 9.1epss 0.00

    Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

  • CVE-2024-10124CriDec 12, 2024
    risk 0.59cvss 9.8epss 0.33

    The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes…

  • CVE-2024-46627CriSep 26, 2024
    risk 0.59cvss 9.1epss 0.04

    Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.