CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,292 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 40 of 126
- CVE-2023-23752CRITICALCVSS 5.3EG 9.0⚠ KEV2023-02-16
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- CVE-2023-23835HIGHCVSS 5.9EG 7.52023-02-14
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applicat…
- CVE-2023-23908MEDIUMCVSS 6.0EG 6.02023-08-11
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-23911HIGHCVSS 7.5EG 7.52023-03-10
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.
- CVE-2023-23923HIGHCVSS 8.2EG 8.22023-02-17
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized acc…
- CVE-2023-24022CRITICALCVSS 10.0EG 10.02023-01-26
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are…
- CVE-2023-24028CRITICALCVSS 9.8EG 9.82023-01-20
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
- CVE-2023-24058MEDIUMCVSS 4.3EG 4.32023-01-22
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affec…
- CVE-2023-24215CRITICALCVSS 9.1EG 9.12026-05-18
Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.
- CVE-2023-2429CRITICALCVSS 9.8EG 9.82023-04-30
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
- CVE-2023-24320CRITICALCVSS 9.8EG 9.82023-02-21
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.
- CVE-2023-24425MEDIUMCVSS 6.5EG 6.52023-01-26
Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kube…
- CVE-2023-24468CRITICALCVSS 9.8EG 9.82023-03-15
Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
- CVE-2023-24479CRITICALCVSS 9.8EG 9.82023-10-11
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger…
- CVE-2023-24481MEDIUMCVSS 6.3EG 6.32024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-24484MEDIUMCVSS 5.5EG 5.52023-02-16
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
- CVE-2023-24485HIGHCVSS 7.8EG 7.82023-02-16
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
- CVE-2023-24486MEDIUMCVSS 5.5EG 5.52023-07-10
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same …
- CVE-2023-24489CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-10
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
- CVE-2023-24490MEDIUMCVSS 6.3EG 6.32023-07-10
Users with only access to launch VDA applications can launch an unauthorized desktop
- CVE-2023-24512HIGHCVSS 8.8EG 8.82023-04-25
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Te…
- CVE-2023-24544HIGHCVSS 8.1EG 8.12023-04-11
Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follow…
- CVE-2023-24546HIGHCVSS 8.1EG 8.12023-06-13
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration da…
- CVE-2023-24688MEDIUMCVSS 5.3EG 5.32023-02-09
An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.
- CVE-2023-24844HIGHCVSS 8.4EG 8.42023-10-03
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
- CVE-2023-24905HIGHCVSS 7.8EG 7.82023-05-09
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2023-25073MEDIUMCVSS 5.5EG 5.52024-02-14
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-25149HIGHCVSS 8.8EG 8.82023-02-14
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run…
- CVE-2023-25150MEDIUMCVSS 5.8EG 5.82023-02-08
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with…
- CVE-2023-25159LOWCVSS 2.3EG 2.32023-02-13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1…
- CVE-2023-25161LOWCVSS 3.7EG 3.72023-02-13
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset function…
- CVE-2023-25174HIGHCVSS 6.7EG 7.82024-02-14
Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-2530CRITICALCVSS 9.8EG 9.82023-06-07
A privilege escalation allowing remote code execution was discovered in the orchestration service.
- CVE-2023-25496HIGHCVSS 7.8EG 7.82023-04-28
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.
- CVE-2023-25525HIGHCVSS 7.5EG 7.52023-09-20
NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful e…
- CVE-2023-25542HIGHCVSS 7.0EG 7.82023-04-06
Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges.
- CVE-2023-25595MEDIUMCVSS 5.5EG 5.52023-03-22
A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to r…
- CVE-2023-25605HIGHCVSS 7.5EG 7.52023-03-07
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
- CVE-2023-25632MEDIUMCVSS 5.5EG 5.52023-11-27
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.
- CVE-2023-25757HIGHCVSS 7.3EG 7.32023-08-11
Improper access control in some Intel(R) Unison(TM) software before version 10.12 may allow a privileged user to potentially enable escalation of privilege via network access.
- CVE-2023-2576MEDIUMCVSS 4.3EG 4.32023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CO…
- CVE-2023-25771MEDIUMCVSS 5.8EG 5.82023-05-10
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
- CVE-2023-25773HIGHCVSS 7.5EG 7.52023-08-11
Improper access control in the Intel(R) Unite(R) Hub software installer for Windows before version 4.2.34962 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-25775MEDIUMCVSS 5.6EG 5.62023-08-11
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2023-25777HIGHCVSS 7.9EG 7.92024-02-14
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-25821MEDIUMCVSS 5.7EG 5.72023-02-25
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissi…
- CVE-2023-26205HIGHCVSS 8.1EG 8.12023-11-14
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges t…
- CVE-2023-26347HIGHCVSS 7.5EG 7.52023-11-17
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability…
- CVE-2023-26360CRITICALCVSS 8.6EG 9.0⚠ KEV2023-03-23
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
- CVE-2023-26406HIGHCVSS 7.8EG 7.82023-04-12
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →