VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 63 of 405
  • CVE-2024-37341HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    Microsoft SQL Server Elevation of Privilege Vulnerability

  • CVE-2024-42023HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.00

    An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

  • CVE-2024-45233CriAug 29, 2024
    risk 0.57cvss 9.8epss 0.00

    An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, resulting in Broken Access Control. Depending on the configuration of the…

  • CVE-2024-24986HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-40475HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.01

    SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.

  • CVE-2024-40531HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.00

    A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.

  • CVE-2024-6737HigJul 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account.

  • CVE-2024-23663HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.

  • CVE-2024-37905HigJun 28, 2024
    risk 0.57cvss 8.8epss 0.01

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik…

  • CVE-2022-45929HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.00

    Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.

  • CVE-2024-27855HigJun 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. A shortcut may be able to use sensitive data with certain actions without prompting the user.

  • CVE-2024-33227HigMay 22, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

  • CVE-2023-52801HigMay 21, 2024
    risk 0.57cvss 8.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree, pages_nodes have to be properly…

  • CVE-2023-45217HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40070HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-32507HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the…

  • CVE-2023-38298HigApr 22, 2024
    risk 0.57cvss 8.8epss 0.00

    Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining…

  • CVE-2024-31759HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.

  • CVE-2024-21115HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-21114HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…