CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 43 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54391 | Cri | 0.59 | 9.1 | 0.01 | Sep 16, 2025 | A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party… | ||
| CVE-2025-55244 | Cri | 0.59 | 9.0 | 0.01 | Sep 4, 2025 | Azure Bot Service Elevation of Privilege Vulnerability | ||
| CVE-2024-45438 | Cri | 0.59 | 9.1 | 0.01 | Aug 21, 2025 | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a… | ||
| CVE-2025-49603 | Cri | 0.59 | 9.1 | 0.00 | Jun 26, 2025 | Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. | ||
| CVE-2025-44619 | Cri | 0.59 | 9.1 | 0.00 | May 30, 2025 | Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication. | ||
| CVE-2025-30436 | Cri | 0.59 | 9.1 | 0.00 | May 12, 2025 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls. | ||
| CVE-2024-48905 | Cri | 0.59 | 9.1 | 0.00 | May 1, 2025 | Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint. | ||
| CVE-2025-28104 | Cri | 0.59 | 9.1 | 0.00 | Apr 21, 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. | ||
| CVE-2025-28233 | Cri | 0.59 | 9.1 | 0.00 | Apr 18, 2025 | Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to… | ||
| CVE-2025-28231 | Cri | 0.59 | 9.1 | 0.00 | Apr 18, 2025 | Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges. | ||
| CVE-2025-28232 | Cri | 0.59 | 9.1 | 0.01 | Apr 18, 2025 | Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication. | ||
| CVE-2025-3113 | Cri | 0.59 | — | 0.00 | Apr 17, 2025 | A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the application’s built-in Connector functionality to access Continuous Compliance’s internal database. This allows the user to… | ||
| CVE-2025-22940 | Cri | 0.59 | 9.1 | 0.00 | Mar 31, 2025 | Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password. | ||
| CVE-2025-30132 | Cri | 0.59 | 9.1 | 0.00 | Mar 18, 2025 | An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. During analysis, it was found that this domain was not owned by IROAD, allowing an attacker to register it and potentially intercept… | ||
| CVE-2025-1260 | Cri | 0.59 | 9.1 | 0.00 | Mar 4, 2025 | On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch. | ||
| CVE-2025-1941 | Cri | 0.59 | 9.1 | 0.00 | Mar 4, 2025 | Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136. | ||
| CVE-2024-37567 | Cri | 0.59 | 9.1 | 0.00 | Feb 27, 2025 | Infoblox NIOS through 8.6.4 has Improper Access Control for Grids. | ||
| CVE-2020-35546 | Cri | 0.59 | 9.1 | 0.00 | Feb 19, 2025 | Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings. | ||
| CVE-2024-10124 | Cri | 0.59 | 9.8 | 0.33 | Dec 12, 2024 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes… | ||
| CVE-2024-46627 | Cri | 0.59 | 9.1 | 0.04 | Sep 26, 2024 | Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests. |
- risk 0.59cvss 9.1epss 0.01
A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party…
- risk 0.59cvss 9.0epss 0.01
Azure Bot Service Elevation of Privilege Vulnerability
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a…
- risk 0.59cvss 9.1epss 0.00
Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
- risk 0.59cvss 9.1epss 0.00
Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.
- risk 0.59cvss 9.1epss 0.00
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.
- risk 0.59cvss 9.1epss 0.00
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to…
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.
- risk 0.59cvss 9.1epss 0.01
Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.
- risk 0.59cvss —epss 0.00
A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the application’s built-in Connector functionality to access Continuous Compliance’s internal database. This allows the user to…
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.
- risk 0.59cvss 9.1epss 0.00
An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. During analysis, it was found that this domain was not owned by IROAD, allowing an attacker to register it and potentially intercept…
- risk 0.59cvss 9.1epss 0.00
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
- risk 0.59cvss 9.1epss 0.00
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.
- risk 0.59cvss 9.1epss 0.00
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
- risk 0.59cvss 9.1epss 0.00
Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.
- risk 0.59cvss 9.8epss 0.33
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes…
- risk 0.59cvss 9.1epss 0.04
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.