VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 67 of 405
  • CVE-2019-10127HigMar 19, 2021
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration,…

  • CVE-2021-25672HigMar 15, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts.

  • CVE-2020-25629HigDec 8, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5…

  • CVE-2020-7547HigDec 1, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege…

  • CVE-2020-26072HigNov 18, 2020
    risk 0.57cvss 8.7epss 0.01

    A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An…

  • CVE-2020-5396HigJul 31, 2020
    risk 0.57cvss 8.8epss 0.02

    VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a…

  • CVE-2020-8207HigJul 24, 2020
    risk 0.57cvss 8.8epss 0.02

    Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.

  • CVE-2020-9046HigMay 26, 2020
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.

  • CVE-2020-12889CriMay 15, 2020
    risk 0.57cvss 9.8epss 0.01

    MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.

  • CVE-2019-5162HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell…

  • CVE-2019-5136HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.02

    An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An…

  • CVE-2019-15589HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

  • CVE-2019-15956HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization…

  • CVE-2019-12648HigSep 25, 2019
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect role-based access…

  • CVE-2019-6810HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.02

    CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol.

  • CVE-2018-20957HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.01

    The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.

  • CVE-2016-10802HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).

  • CVE-2016-10792HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).

  • CVE-2016-10820HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).

  • CVE-2019-10138HigJul 30, 2019
    risk 0.57cvss 8.8epss 0.01

    A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.