VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 34 of 187
  • CVE-2023-24546HigJun 13, 2023
    risk 0.53cvss 8.1epss 0.00

    On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This…

  • CVE-2023-32220HigJun 12, 2023
    risk 0.53cvss 8.2epss 0.01

    Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.

  • CVE-2023-3066HigJun 5, 2023
    risk 0.53cvss 8.1epss 0.01

    Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mobatime mobile application AMXGT100: through 1.3.20.

  • CVE-2023-31435HigMay 2, 2023
    risk 0.53cvss 8.1epss 0.01

    Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allow authenticated attackers to read and write to unauthorized data by accessing…

  • CVE-2023-25017HigMar 27, 2023
    risk 0.53cvss 8.1epss 0.01

    RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform specific privileged function to access and modify all sensitive data.

  • CVE-2023-26484HigMar 15, 2023
    risk 0.53cvss 8.2epss 0.01

    KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs.…

  • CVE-2023-24880MedKEVMar 14, 2023
    risk 0.53cvss 4.4epss 0.78

    Windows SmartScreen Security Feature Bypass Vulnerability

  • CVE-2023-22891HigMar 8, 2023
    risk 0.53cvss 8.1epss 0.01

    There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.

  • CVE-2023-25559HigFeb 11, 2023
    risk 0.53cvss 8.2epss 0.01

    DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is sending the request on behalf of. When…

  • CVE-2022-41091MedKEVNov 9, 2022
    risk 0.53cvss 5.4epss 0.02

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2022-34046HigJul 20, 2022
    risk 0.53cvss 7.5epss 0.20

    An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].

  • CVE-2021-23175HigDec 23, 2021
    risk 0.53cvss 8.2epss 0.00

    NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data…

  • CVE-2021-42135HigOct 11, 2021
    risk 0.53cvss 8.1epss 0.01

    HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the…

  • CVE-2021-39156HigAug 24, 2021
    risk 0.53cvss 8.1epss 0.01

    Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability…

  • CVE-2021-38137HigAug 6, 2021
    risk 0.53cvss 8.1epss 0.01

    Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.

  • CVE-2021-1540HigJun 4, 2021
    risk 0.53cvss 8.1epss 0.01

    Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities,…

  • CVE-2021-1539HigJun 4, 2021
    risk 0.53cvss 8.1epss 0.01

    Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities,…

  • CVE-2020-26560HigMay 24, 2021
    risk 0.53cvss 8.1epss 0.01

    Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.

  • CVE-2021-29452HigApr 16, 2021
    risk 0.53cvss 8.1epss 0.01

    a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged…

  • CVE-2021-26563HigFeb 26, 2021
    risk 0.53cvss 8.2epss 0.01

    Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.