CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 38 of 126
- CVE-2023-1524MEDIUMCVSS 6.5EG 6.52023-05-30
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protect…
- CVE-2023-1555LOWCVSS 2.7EG 2.72023-09-01
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. A namespace-level banned user can access the API.
- CVE-2023-1557CRITICALCVSS 6.3EG 9.82023-03-22
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ecommerce/admin/user/controller.php?action=edit of the component Username H…
- CVE-2023-1647HIGHCVSS 8.8EG 8.82023-03-27
Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.
- CVE-2023-1832MEDIUMCVSS 6.8EG 6.82023-10-04
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
- CVE-2023-1834CRITICALCVSS 9.4EG 9.42023-05-11
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized a…
- CVE-2023-1862HIGHCVSS 7.3EG 7.32023-06-20
Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an attacker to trigge…
- CVE-2023-1883MEDIUMCVSS 5.4EG 5.42023-04-05
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- CVE-2023-1936LOWCVSS 3.5EG 3.52023-07-11
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the emai…
- CVE-2023-20065HIGHCVSS 7.8EG 7.82023-03-23
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restric…
- CVE-2023-20191MEDIUMCVSS 5.8EG 5.82023-09-13
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to in…
- CVE-2023-2022MEDIUMCVSS 4.3EG 4.32023-08-02
An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeli…
- CVE-2023-20223HIGHCVSS 8.6EG 8.62023-09-27
A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access cont…
- CVE-2023-20224HIGHCVSS 7.8EG 7.82023-08-16
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insuf…
- CVE-2023-20230MEDIUMCVSS 5.4EG 5.42023-08-23
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access…
- CVE-2023-20237MEDIUMCVSS 4.3EG 4.32023-08-16
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internal…
- CVE-2023-20260MEDIUMCVSS 6.0EG 6.02024-01-17
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing…
- CVE-2023-20261MEDIUMCVSS 6.5EG 6.52023-10-18
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are se…
- CVE-2023-20267MEDIUMCVSS 4.0EG 4.02023-11-01
A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parse…
- CVE-2023-20579MEDIUMCVSS 6.0EG 6.02024-02-13
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
- CVE-2023-20587HIGHCVSS 7.1EG 7.12024-02-13
Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.
- CVE-2023-20927HIGHCVSS 7.8EG 7.82023-02-15
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
- CVE-2023-2104MEDIUMCVSS 5.4EG 5.42023-04-15
Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- CVE-2023-2112LOWCVSS 3.6EG 3.62023-04-20
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
- CVE-2023-21427MEDIUMCVSS 5.4EG 6.52023-02-09
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.
- CVE-2023-21438LOWCVSS 2.1EG 2.42023-02-09
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
- CVE-2023-21442MEDIUMCVSS 4.0EG 5.52023-02-09
Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.
- CVE-2023-21445HIGHCVSS 5.5EG 7.82023-02-09
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
- CVE-2023-21447MEDIUMCVSS 4.0EG 4.02023-02-09
Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.
- CVE-2023-21457HIGHCVSS 4.1EG 8.12023-03-16
Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
- CVE-2023-21463MEDIUMCVSS 4.0EG 4.02023-03-16
Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Inte…
- CVE-2023-21465MEDIUMCVSS 5.5EG 5.52023-03-16
Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.
- CVE-2023-21488MEDIUMCVSS 4.4EG 4.42023-05-04
Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
- CVE-2023-21490MEDIUMCVSS 4.7EG 4.72023-05-04
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
- CVE-2023-21491HIGHCVSS 8.5EG 8.52023-05-04
Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.
- CVE-2023-21493MEDIUMCVSS 6.8EG 6.82023-05-04
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
- CVE-2023-21495MEDIUMCVSS 4.0EG 4.02023-05-04
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
- CVE-2023-21518MEDIUMCVSS 4.4EG 4.42023-06-28
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
- CVE-2023-21531HIGHCVSS 7.0EG 7.02023-01-10
Azure Service Fabric Container Elevation of Privilege Vulnerability
- CVE-2023-2159MEDIUMCVSS 5.3EG 5.32023-06-09
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default set…
- CVE-2023-21642HIGHCVSS 8.4EG 8.42023-05-02
Memory corruption in HAB Memory management due to broad system privileges via physical address.
- CVE-2023-21670HIGHCVSS 7.8EG 7.82023-06-06
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
- CVE-2023-21673HIGHCVSS 8.7EG 8.72023-10-03
Improper Access to the VM resource manager can lead to Memory Corruption.
- CVE-2023-21717HIGHCVSS 8.8EG 8.82023-02-14
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2023-21742HIGHCVSS 8.8EG 8.92023-01-10
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-21750HIGHCVSS 7.1EG 7.12023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21751MEDIUMCVSS 6.5EG 6.52023-12-14
Azure DevOps Server Spoofing Vulnerability
- CVE-2023-21752HIGHCVSS 7.1EG 7.12023-01-10
Windows Backup Service Elevation of Privilege Vulnerability
- CVE-2023-21777HIGHCVSS 8.7EG 8.72023-02-14
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
- CVE-2023-21828HIGHCVSS 8.1EG 8.12023-01-18
Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privile…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →