CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 67 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10127 | Hig | 0.57 | 8.8 | 0.00 | Mar 19, 2021 | A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration,… | ||
| CVE-2021-25672 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2021 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts. | ||
| CVE-2020-25629 | Hig | 0.57 | 8.8 | 0.01 | Dec 8, 2020 | A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5… | ||
| CVE-2020-7547 | Hig | 0.57 | 8.8 | 0.01 | Dec 1, 2020 | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege… | ||
| CVE-2020-26072 | Hig | 0.57 | 8.7 | 0.01 | Nov 18, 2020 | A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An… | ||
| CVE-2020-5396 | Hig | 0.57 | 8.8 | 0.02 | Jul 31, 2020 | VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a… | ||
| CVE-2020-8207 | Hig | 0.57 | 8.8 | 0.02 | Jul 24, 2020 | Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. | ||
| CVE-2020-9046 | Hig | 0.57 | 8.8 | 0.00 | May 26, 2020 | A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files. | ||
| CVE-2020-12889 | Cri | 0.57 | 9.8 | 0.01 | May 15, 2020 | MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. | ||
| CVE-2019-5162 | Hig | 0.57 | 8.8 | 0.03 | Feb 25, 2020 | An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell… | ||
| CVE-2019-5136 | Hig | 0.57 | 8.8 | 0.02 | Feb 25, 2020 | An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An… | ||
| CVE-2019-15589 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2019 | An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. | ||
| CVE-2019-15956 | Hig | 0.57 | 8.8 | 0.01 | Nov 26, 2019 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization… | ||
| CVE-2019-12648 | Hig | 0.57 | 8.8 | 0.02 | Sep 25, 2019 | A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect role-based access… | ||
| CVE-2019-6810 | Hig | 0.57 | 8.8 | 0.02 | Sep 17, 2019 | CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol. | ||
| CVE-2018-20957 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2019 | The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks. | ||
| CVE-2016-10802 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142). | ||
| CVE-2016-10792 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). | ||
| CVE-2016-10820 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31). | ||
| CVE-2019-10138 | Hig | 0.57 | 8.8 | 0.01 | Jul 30, 2019 | A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens. |
- risk 0.57cvss 8.8epss 0.00
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration,…
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts.
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5…
- risk 0.57cvss 8.8epss 0.01
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege…
- risk 0.57cvss 8.7epss 0.01
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An…
- risk 0.57cvss 8.8epss 0.02
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a…
- risk 0.57cvss 8.8epss 0.02
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.
- risk 0.57cvss 8.8epss 0.00
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
- risk 0.57cvss 9.8epss 0.01
MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
- risk 0.57cvss 8.8epss 0.03
An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell…
- risk 0.57cvss 8.8epss 0.02
An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An…
- risk 0.57cvss 8.8epss 0.01
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization…
- risk 0.57cvss 8.8epss 0.02
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect role-based access…
- risk 0.57cvss 8.8epss 0.02
CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol.
- risk 0.57cvss 8.8epss 0.01
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
- risk 0.57cvss 8.8epss 0.01
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
- risk 0.57cvss 8.8epss 0.01
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
- risk 0.57cvss 8.8epss 0.01
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.