VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 9 of 82
  • CVE-2021-36276HigAug 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

  • CVE-2021-1576HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific…

  • CVE-2021-1574HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific…

  • CVE-2021-24195HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary…

  • CVE-2021-24194HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate…

  • CVE-2021-24193HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary…

  • CVE-2021-24192HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which…

  • CVE-2021-24191HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate…

  • CVE-2021-24190HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary…

  • CVE-2021-24189HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate…

  • CVE-2021-24188HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate…

  • CVE-2020-24674HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.03

    In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.

  • CVE-2020-7530HigSep 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.

  • CVE-2020-3386HigJul 31, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of…

  • CVE-2019-13554HigApr 7, 2020
    risk 0.57cvss 8.8epss 0.01

    GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. GE recommends that users disable the Telnet service.

  • CVE-2019-1907HigAug 21, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations…

  • CVE-2018-14670CriAug 15, 2019
    risk 0.57cvss 9.8epss 0.02

    Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.

  • CVE-2019-1934HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to elevate privileges and execute administrative functions on an affected device. The vulnerability is due to insufficient…

  • CVE-2018-17210HigJul 20, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level…

  • CVE-2018-19569HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.02

    GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.