VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 78 of 405
  • CVE-2021-33162HigFeb 23, 2024
    risk 0.55cvss 8.4epss 0.00

    Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-43517HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Multimedia due to improper access control in HAB.

  • CVE-2023-33071HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.

  • CVE-2023-31100HigNov 15, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 before 4.3.1.163 * from 4.4.0.0 before…

  • CVE-2023-29157HigNov 14, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-41679HigOct 10, 2023
    risk 0.55cvss 8.5epss 0.01

    An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission…

  • CVE-2023-24844HigOct 3, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.

  • CVE-2023-22014HigJul 18, 2023
    risk 0.55cvss 8.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft…

  • CVE-2023-21491HigMay 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.

  • CVE-2023-21642HigMay 2, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in HAB Memory management due to broad system privileges via physical address.

  • CVE-2022-40539HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Android OS due to improper validation of array index.

  • CVE-2022-33243HigFeb 12, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to improper access control in Qualcomm IPC.

  • CVE-2022-27836HigApr 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary…

  • CVE-2021-35245HigDec 6, 2021
    risk 0.55cvss 8.4epss 0.01

    When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

  • CVE-2016-4383HigJun 27, 2017
    risk 0.55cvss 8.4epss 0.03

    The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.

  • CVE-2016-9976HigMay 3, 2017
    risk 0.55cvss 8.4epss 0.02

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.

  • CVE-2017-3523HigApr 24, 2017
    risk 0.55cvss 8.5epss 0.03

    Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2015-4624HigMar 31, 2017
    risk 0.55cvss 7.5epss 0.37

    Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.

  • CVE-2016-0392HigJun 19, 2016
    risk 0.55cvss 8.4epss 0.01

    IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a…

  • CVE-2015-6862HigJan 8, 2016
    risk 0.55cvss 8.4epss 0.01

    HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.