CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 32 of 126
- CVE-2022-29160LOWCVSS 2.8EG 2.82022-05-20
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of …
- CVE-2022-29417MEDIUMCVSS 4.3EG 4.32022-04-25
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
- CVE-2022-29871MEDIUMCVSS 6.7EG 6.72023-08-11
Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-2995HIGHCVSS 7.1EG 7.12022-09-19
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups…
- CVE-2022-3019HIGHCVSS 8.8EG 8.82022-08-29
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long tim…
- CVE-2022-3027MEDIUMCVSS 5.7EG 5.72022-09-13
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to t…
- CVE-2022-3030MEDIUMCVSS 4.3EG 4.32022-10-17
An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.
- CVE-2022-30564MEDIUMCVSS 5.3EG 5.32023-02-09
Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time.
- CVE-2022-3065HIGHCVSS 7.5EG 7.52022-09-02
Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
- CVE-2022-3066MEDIUMCVSS 5.4EG 5.42022-10-17
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to creat…
- CVE-2022-3067MEDIUMCVSS 6.5EG 6.52022-10-17
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible…
- CVE-2022-30715MEDIUMCVSS 4.0EG 5.32022-06-07
Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.
- CVE-2022-30745MEDIUMCVSS 4.0EG 5.52022-06-07
Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.
- CVE-2022-30750LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
- CVE-2022-30751LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
- CVE-2022-30752LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
- CVE-2022-3082MEDIUMCVSS 6.5EG 6.52022-10-17
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example
- CVE-2022-31024MEDIUMCVSS 6.5EG 6.52022-06-02
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. …
- CVE-2022-31055HIGHCVSS 7.5EG 7.52022-06-13
kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workarou…
- CVE-2022-31231HIGHCVSS 7.5EG 7.52026-05-22
Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthor…
- CVE-2022-31257HIGHCVSS 7.5EG 7.52022-07-12
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applicat…
- CVE-2022-31475MEDIUMCVSS 5.5EG 5.52022-07-21
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
- CVE-2022-31687CRITICALCVSS 9.8EG 9.82022-11-09
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the ap…
- CVE-2022-31704CRITICALCVSS 9.8EG 9.82023-01-26
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
- CVE-2022-31708MEDIUMCVSS 4.9EG 4.92022-12-16
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
- CVE-2022-3182HIGHCVSS 7.0EG 7.02022-09-13
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 202…
- CVE-2022-3186HIGHCVSS 8.6EG 8.62022-12-21
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect dev…
- CVE-2022-32158CRITICALCVSS 9.0EG 10.02022-06-15
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint …
- CVE-2022-32212HIGHCVSS 8.1EG 8.12022-07-14
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid befo…
- CVE-2022-32226MEDIUMCVSS 4.3EG 4.32022-09-23
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accepted by the server, …
- CVE-2022-32255MEDIUMCVSS 5.3EG 5.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized acces…
- CVE-2022-32256MEDIUMCVSS 4.3EG 6.52022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged use…
- CVE-2022-32257CRITICALCVSS 9.8EG 9.82024-03-12
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized acces…
- CVE-2022-32507HIGHCVSS 8.8EG 8.82024-05-14
An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no acces…
- CVE-2022-32578MEDIUMCVSS 6.7EG 6.72023-05-10
Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-32582MEDIUMCVSS 5.3EG 5.32023-05-10
Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service vi…
- CVE-2022-3263HIGHCVSS 7.8EG 7.82022-09-23
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.
- CVE-2022-32783MEDIUMCVSS 5.5EG 5.52022-09-23
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.
- CVE-2022-32789MEDIUMCVSS 5.5EG 5.52022-09-23
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypass Privacy preferences.
- CVE-2022-32800MEDIUMCVSS 5.5EG 5.52022-09-23
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.
- CVE-2022-32834MEDIUMCVSS 5.5EG 5.52022-08-24
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.
- CVE-2022-32848MEDIUMCVSS 5.5EG 5.52022-09-23
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a user’s screen.
- CVE-2022-3286MEDIUMCVSS 5.3EG 5.32022-10-17
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token
- CVE-2022-32872LOWCVSS 2.4EG 2.42022-09-20
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.
- CVE-2022-32880MEDIUMCVSS 6.5EG 6.52022-09-20
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.
- CVE-2022-32883MEDIUMCVSS 5.5EG 5.52022-09-20
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
- CVE-2022-32902MEDIUMCVSS 5.5EG 5.52023-02-27
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.
- CVE-2022-32904MEDIUMCVSS 5.5EG 5.52022-11-01
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An app may be able to access user-sensitive data.
- CVE-2022-32918MEDIUMCVSS 5.5EG 5.52022-11-01
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.
- CVE-2022-32945MEDIUMCVSS 4.3EG 4.32022-12-15
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →