VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 96 of 405
  • CVE-2022-36396HigNov 14, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-26205HigNov 14, 2023
    risk 0.53cvss 8.1epss 0.01

    An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted…

  • CVE-2023-30969HigOct 26, 2023
    risk 0.53cvss 8.2epss 0.00

    The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.

  • CVE-2023-43696HigOct 9, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.

  • CVE-2023-22618HigOct 4, 2023
    risk 0.53cvss 8.1epss 0.00

    If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite…

  • CVE-2023-31242HigSep 5, 2023
    risk 0.53cvss 8.1epss 0.03

    An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this…

  • CVE-2023-28714HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-27635HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-3271HigJul 10, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

  • CVE-2023-35939HigJul 5, 2023
    risk 0.53cvss 8.1epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard…

  • CVE-2023-24546HigJun 13, 2023
    risk 0.53cvss 8.1epss 0.00

    On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This…

  • CVE-2022-40207HigMay 10, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-45111HigApr 25, 2023
    risk 0.53cvss 8.1epss 0.01

    Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.

  • CVE-2023-24544HigApr 11, 2023
    risk 0.53cvss 8.1epss 0.00

    Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03…

  • CVE-2023-21828HigJan 18, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2022-47634HigJan 1, 2023
    risk 0.53cvss 8.1epss 0.00

    M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867.

  • CVE-2022-46664HigDec 13, 2022
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module…

  • CVE-2022-45936HigDec 13, 2022
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read and manipulate sensitive information.

  • CVE-2022-37918HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2022-37917HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…