VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 66 of 405
  • CVE-2023-21832HigJan 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple…

  • CVE-2022-4724CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-42861HigDec 15, 2022
    risk 0.57cvss 8.8epss 0.00

    This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.

  • CVE-2022-45937HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact…

  • CVE-2022-44037HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin rights without authenticating allows him…

  • CVE-2022-38743HigOct 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the…

  • CVE-2022-23768HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.

  • CVE-2020-4107HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.00

    HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.

  • CVE-2022-21182HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.02

    A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-36776HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

  • CVE-2021-36775HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

  • CVE-2021-40416HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an…

  • CVE-2022-0270HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.

  • CVE-2021-42124HigDec 7, 2021
    risk 0.57cvss 8.8epss 0.03

    An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.

  • CVE-2021-36909HigNov 18, 2021
    risk 0.57cvss 8.8epss 0.02

    Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.

  • CVE-2021-34864HigOct 25, 2021
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The…

  • CVE-2021-41298HigSep 30, 2021
    risk 0.57cvss 8.8epss 0.01

    ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and…

  • CVE-2021-32652HigJun 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1.8.2 contain patches for this vulnerability; no workarounds…

  • CVE-2021-28798HigMay 21, 2021
    risk 0.57cvss 8.8epss 0.01

    A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerability in the following versions: QTS…

  • CVE-2021-1284HigMay 6, 2021
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. To exploit this vulnerability, the…