CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 44 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38220 | Cri | 0.59 | 9.0 | 0.01 | Sep 10, 2024 | Azure Stack Hub Elevation of Privilege Vulnerability | ||
| CVE-2024-42775 | Cri | 0.59 | 9.1 | 0.00 | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access. | ||
| CVE-2024-28805 | Cri | 0.59 | 9.1 | 0.00 | Jul 29, 2024 | An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control. | ||
| CVE-2024-22187 | Cri | 0.59 | 9.1 | 0.01 | May 28, 2024 | A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to… | ||
| CVE-2024-31967 | Cri | 0.59 | 9.1 | 0.00 | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A… | ||
| CVE-2024-21071 | Cri | 0.59 | 9.1 | 0.01 | Apr 16, 2024 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise… | ||
| CVE-2024-24486 | Cri | 0.59 | 9.1 | 0.01 | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command. | ||
| CVE-2024-25852 | Hig | 0.59 | 8.8 | 0.17 | Apr 11, 2024 | Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights. | ||
| CVE-2024-27602 | Cri | 0.59 | 9.1 | 0.00 | Apr 2, 2024 | Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module. | ||
| CVE-2024-29866 | Cri | 0.59 | 9.1 | 0.01 | Mar 21, 2024 | Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges. | ||
| CVE-2020-26942 | Cri | 0.59 | 9.1 | 0.00 | Mar 21, 2024 | An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account. | ||
| CVE-2021-47155 | Cri | 0.59 | 9.1 | 0.01 | Mar 18, 2024 | The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses. | ||
| CVE-2023-51786 | Cri | 0.59 | 9.1 | 0.01 | Mar 7, 2024 | An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control. | ||
| CVE-2024-27497 | Hig | 0.59 | 8.8 | 0.27 | Mar 1, 2024 | Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file. | ||
| CVE-2024-21376 | Cri | 0.59 | 9.0 | 0.01 | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | ||
| CVE-2024-25106 | Cri | 0.59 | 9.1 | 0.00 | Feb 8, 2024 | OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user… | ||
| CVE-2022-46025 | Cri | 0.59 | 9.1 | 0.01 | Jan 10, 2024 | Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page. | ||
| CVE-2023-46501 | Cri | 0.59 | 9.1 | 0.01 | Nov 7, 2023 | An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function. | ||
| CVE-2023-44118 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2023-34034 | Cri | 0.59 | 9.1 | 0.04 | Jul 19, 2023 | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass. |
- risk 0.59cvss 9.0epss 0.01
Azure Stack Hub Elevation of Privilege Vulnerability
- risk 0.59cvss 9.1epss 0.00
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.
- risk 0.59cvss 9.1epss 0.00
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
- risk 0.59cvss 9.1epss 0.01
A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to…
- risk 0.59cvss 9.1epss 0.00
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A…
- risk 0.59cvss 9.1epss 0.01
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…
- risk 0.59cvss 9.1epss 0.01
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.
- risk 0.59cvss 8.8epss 0.17
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
- risk 0.59cvss 9.1epss 0.00
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.
- risk 0.59cvss 9.1epss 0.01
Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.
- risk 0.59cvss 9.1epss 0.00
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.
- risk 0.59cvss 9.1epss 0.01
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.
- risk 0.59cvss 8.8epss 0.27
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
- risk 0.59cvss 9.0epss 0.01
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.00
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user…
- risk 0.59cvss 9.1epss 0.01
Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page.
- risk 0.59cvss 9.1epss 0.01
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.59cvss 9.1epss 0.04
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.