VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 95 of 405
  • CVE-2024-32483HigNov 13, 2024
    risk 0.53cvss 8.2epss 0.00

    Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-48955HigOct 29, 2024
    risk 0.53cvss 8.1epss 0.01

    Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of…

  • CVE-2024-46539HigOct 8, 2024
    risk 0.53cvss 8.2epss 0.00

    Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).

  • CVE-2024-42514HigOct 1, 2024
    risk 0.53cvss 8.1epss 0.00

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could…

  • CVE-2024-46097HigSep 27, 2024
    risk 0.53cvss 8.1epss 0.00

    TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application…

  • CVE-2024-6796HigSep 9, 2024
    risk 0.53cvss 8.2epss 0.00

    In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.

  • CVE-2024-45170HigSep 4, 2024
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of the C-MOR web interface. It was found out that different functions are only available to administrative…

  • CVE-2024-7525HigAug 6, 2024
    risk 0.53cvss 8.1epss 0.01

    It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and…

  • CVE-2024-21153HigJul 16, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2024-37742HigJun 25, 2024
    risk 0.53cvss 8.2epss 0.01

    Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls…

  • CVE-2022-23829HigJun 18, 2024
    risk 0.53cvss 8.2epss 0.00

    A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.

  • CVE-2024-35433HigMay 30, 2024
    risk 0.53cvss 8.1epss 0.00

    ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

  • CVE-2024-22811HigApr 22, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the Hostmot2 configuration cookie in the device memory.

  • CVE-2023-36554HigMar 12, 2024
    risk 0.53cvss 8.1epss 0.01

    A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

  • CVE-2023-22293HigFeb 14, 2024
    risk 0.53cvss 8.2epss 0.00

    Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-24824HigFeb 7, 2024
    risk 0.53cvss 8.8epss 0.35

    Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses…

  • CVE-2024-0324HigFeb 5, 2024
    risk 0.53cvss 8.2epss 0.02

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all…

  • CVE-2024-0212HigJan 29, 2024
    risk 0.53cvss 8.1epss 0.01

    The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.

  • CVE-2024-23681HigJan 19, 2024
    risk 0.53cvss 8.2epss 0.00

    Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.

  • CVE-2023-29051HigJan 8, 2024
    risk 0.53cvss 8.1epss 0.01

    User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects…