VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 64 of 405
  • CVE-2024-21113HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-21112HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2024-21067HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure…

  • CVE-2024-29837HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.

  • CVE-2024-29993HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Azure CycleCloud Elevation of Privilege Vulnerability

  • CVE-2023-50702HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.

  • CVE-2023-49978HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

  • CVE-2024-25501HigMar 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.

  • CVE-2024-28115HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.00

    FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution.…

  • CVE-2023-43318HigMar 6, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

  • CVE-2023-38946HigMar 6, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplying a crafted cookie.

  • CVE-2024-1632HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

  • CVE-2024-25251HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.01

    code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

  • CVE-2023-47422HigFeb 20, 2024
    risk 0.57cvss 8.8epss 0.00

    An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.

  • CVE-2023-39425HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-25677HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.

  • CVE-2023-47867HigFeb 1, 2024
    risk 0.57cvss 8.8epss 0.00

    MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.

  • CVE-2023-50159HigJan 11, 2024
    risk 0.57cvss 8.8epss 0.00

    In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

  • CVE-2023-32204HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-43336HigNov 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.