VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 44 of 405
  • CVE-2024-38220CriSep 10, 2024
    risk 0.59cvss 9.0epss 0.01

    Azure Stack Hub Elevation of Privilege Vulnerability

  • CVE-2024-42775CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.

  • CVE-2024-28805CriJul 29, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

  • CVE-2024-22187CriMay 28, 2024
    risk 0.59cvss 9.1epss 0.01

    A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to…

  • CVE-2024-31967CriMay 2, 2024
    risk 0.59cvss 9.1epss 0.00

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A…

  • CVE-2024-21071CriApr 16, 2024
    risk 0.59cvss 9.1epss 0.01

    Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…

  • CVE-2024-24486CriApr 15, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.

  • CVE-2024-25852HigApr 11, 2024
    risk 0.59cvss 8.8epss 0.17

    Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.

  • CVE-2024-27602CriApr 2, 2024
    risk 0.59cvss 9.1epss 0.00

    Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.

  • CVE-2024-29866CriMar 21, 2024
    risk 0.59cvss 9.1epss 0.01

    Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.

  • CVE-2020-26942CriMar 21, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.

  • CVE-2021-47155CriMar 18, 2024
    risk 0.59cvss 9.1epss 0.01

    The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

  • CVE-2023-51786CriMar 7, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.

  • CVE-2024-27497HigMar 1, 2024
    risk 0.59cvss 8.8epss 0.27

    Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

  • CVE-2024-21376CriFeb 13, 2024
    risk 0.59cvss 9.0epss 0.01

    Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

  • CVE-2024-25106CriFeb 8, 2024
    risk 0.59cvss 9.1epss 0.00

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user…

  • CVE-2022-46025CriJan 10, 2024
    risk 0.59cvss 9.1epss 0.01

    Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page.

  • CVE-2023-46501CriNov 7, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.

  • CVE-2023-44118CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2023-34034CriJul 19, 2023
    risk 0.59cvss 9.1epss 0.04

    Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.