CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,082)
page 68 of 405| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13028 | Hig | 0.57 | 8.8 | 0.04 | Jun 28, 2019 | An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML page. This is a product from the… | ||
| CVE-2017-11365 | Cri | 0.57 | 9.8 | 0.02 | May 23, 2019 | Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator. | ||
| CVE-2017-8340 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2017-6912 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2019-3779 | Hig | 0.57 | 8.8 | 0.01 | Mar 8, 2019 | Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a cluster to request a signed certificate… | ||
| CVE-2018-17921 | Hig | 0.57 | 8.8 | 0.01 | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction. | ||
| CVE-2018-0436 | Hig | 0.57 | 8.7 | 0.01 | Oct 5, 2018 | A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for… | ||
| CVE-2018-0343 | Hig | 0.57 | 8.8 | 0.02 | Jul 18, 2018 | A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on an affected system. The vulnerability is… | ||
| CVE-2018-4845 | Hig | 0.57 | 8.8 | 0.01 | Jun 26, 2018 | A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products),… | ||
| CVE-2016-9905 | Hig | 0.57 | 8.8 | 0.02 | Jun 11, 2018 | A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6. | ||
| CVE-2014-5279 | Hig | 0.57 | 8.8 | 0.03 | Feb 6, 2018 | The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers. | ||
| CVE-2017-12262 | Hig | 0.57 | 8.8 | 0.01 | Nov 2, 2017 | A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the internal network of the device.… | ||
| CVE-2014-3624 | Cri | 0.57 | 9.8 | 0.04 | Oct 30, 2017 | Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT. | ||
| CVE-2017-8448 | Hig | 0.57 | 8.8 | 0.01 | Sep 29, 2017 | An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges. | ||
| CVE-2014-9831 | Hig | 0.57 | 8.8 | 0.02 | Aug 7, 2017 | coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file. | ||
| CVE-2014-9830 | Hig | 0.57 | 8.8 | 0.02 | Aug 7, 2017 | coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file. | ||
| CVE-2014-9828 | Hig | 0.57 | 8.8 | 0.02 | Aug 7, 2017 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file. | ||
| CVE-2014-9827 | Hig | 0.57 | 8.8 | 0.02 | Aug 7, 2017 | coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file. | ||
| CVE-2016-7824 | Hig | 0.57 | 8.8 | 0.02 | Jun 9, 2017 | Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors. | ||
| CVE-2016-7811 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2017 | Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors. |
- risk 0.57cvss 8.8epss 0.04
An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML page. This is a product from the…
- risk 0.57cvss 9.8epss 0.02
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.
- risk 0.57cvss 8.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.57cvss 8.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.57cvss 8.8epss 0.01
Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a cluster to request a signed certificate…
- risk 0.57cvss 8.8epss 0.01
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction.
- risk 0.57cvss 8.7epss 0.01
A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for…
- risk 0.57cvss 8.8epss 0.02
A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on an affected system. The vulnerability is…
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products),…
- risk 0.57cvss 8.8epss 0.02
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
- risk 0.57cvss 8.8epss 0.03
The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.
- risk 0.57cvss 8.8epss 0.01
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the internal network of the device.…
- risk 0.57cvss 9.8epss 0.04
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
- risk 0.57cvss 8.8epss 0.01
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.
- risk 0.57cvss 8.8epss 0.02
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
- risk 0.57cvss 8.8epss 0.02
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
- risk 0.57cvss 8.8epss 0.02
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.
- risk 0.57cvss 8.8epss 0.02
coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.
- risk 0.57cvss 8.8epss 0.02
Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.