CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,293 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 42 of 126
- CVE-2023-2903MEDIUMCVSS 4.3EG 4.32023-05-25
A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an unknown part of the file /SystemManage/Role/GetGridJson?keyword=&page=1&rows=20. The manipulation leads to improper acce…
- CVE-2023-29051HIGHCVSS 8.1EG 8.12024-01-08
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify ap…
- CVE-2023-29113MEDIUMCVSS 6.3EG 6.32025-06-28
The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine…
- CVE-2023-29115MEDIUMCVSS 6.5EG 6.52024-11-05
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).
- CVE-2023-29121CRITICALCVSS 9.6EG 9.62024-11-05
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
- CVE-2023-29130CRITICALCVSS 9.9EG 9.92023-07-11
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this…
- CVE-2023-29140MEDIUMCVSS 5.3EG 5.32023-03-31
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.
- CVE-2023-29157HIGHCVSS 8.4EG 8.42023-11-14
Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-29164HIGHCVSS 7.3EG 7.32025-02-12
Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before…
- CVE-2023-29242MEDIUMCVSS 6.7EG 6.72023-05-12
Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-29298CRITICALCVSS 7.5EG 9.0⚠ KEV2023-07-12
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage thi…
- CVE-2023-2940MEDIUMCVSS 6.5EG 6.52023-05-30
Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security seve…
- CVE-2023-2944MEDIUMCVSS 5.4EG 6.32023-05-27
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- CVE-2023-2946HIGHCVSS 8.1EG 8.12023-05-27
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- CVE-2023-29513MEDIUMCVSS 5.0EG 5.02023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong …
- CVE-2023-29586MEDIUMCVSS 5.5EG 6.52023-04-19
Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read by allowing any user to copy any directory in the system to a directory they control. NOTE…
- CVE-2023-2979MEDIUMCVSS 4.7EG 4.72023-05-30
A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the at…
- CVE-2023-29921MEDIUMCVSS 5.3EG 5.32023-04-19
PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.
- CVE-2023-29922MEDIUMCVSS 5.3EG 5.32023-04-19
PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.
- CVE-2023-29924CRITICALCVSS 9.8EG 9.82023-04-21
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.
- CVE-2023-3018MEDIUMCVSS 6.3EG 6.32023-05-31
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/?page=user/list. The manipulation leads to improper access cont…
- CVE-2023-3039HIGHCVSS 7.3EG 7.82023-09-12
SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.
- CVE-2023-30539MEDIUMCVSS 6.5EG 6.52023-04-17
Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files …
- CVE-2023-30582MEDIUMCVSS 5.3EG 5.32024-09-07
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to…
- CVE-2023-30583HIGHCVSS 7.5EG 7.52024-09-07
fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that a…
- CVE-2023-30587HIGHCVSS 7.5EG 7.52024-09-07
A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector). By exploiting the Worker class's ability to create an "internal worker…
- CVE-2023-30640MEDIUMCVSS 4.3EG 4.32023-07-06
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
- CVE-2023-30641MEDIUMCVSS 4.3EG 4.32023-07-06
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
- CVE-2023-30667MEDIUMCVSS 5.1EG 5.12023-07-06
Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
- CVE-2023-30676MEDIUMCVSS 4.6EG 4.62023-07-06
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.
- CVE-2023-30677MEDIUMCVSS 6.1EG 6.12023-07-06
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
- CVE-2023-30679HIGHCVSS 7.8EG 7.82023-08-10
Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-30682MEDIUMCVSS 4.3EG 4.32023-08-10
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
- CVE-2023-30683MEDIUMCVSS 4.3EG 4.32023-08-10
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
- CVE-2023-30684MEDIUMCVSS 4.3EG 4.32023-08-10
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
- CVE-2023-30685MEDIUMCVSS 4.3EG 4.32023-08-10
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
- CVE-2023-30698MEDIUMCVSS 5.5EG 5.52023-08-10
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
- CVE-2023-30701MEDIUMCVSS 4.7EG 4.72023-08-10
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
- CVE-2023-30709HIGHCVSS 7.9EG 7.92023-09-06
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
- CVE-2023-30715MEDIUMCVSS 4.0EG 4.02023-09-06
Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
- CVE-2023-30720MEDIUMCVSS 4.7EG 4.72023-09-06
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
- CVE-2023-30726MEDIUMCVSS 4.7EG 4.72023-09-06
PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.
- CVE-2023-30732MEDIUMCVSS 5.5EG 5.52023-10-04
Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.
- CVE-2023-30734MEDIUMCVSS 4.0EG 4.02023-10-04
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
- CVE-2023-30737MEDIUMCVSS 4.0EG 4.02023-10-04
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
- CVE-2023-30765HIGHCVSS 8.8EG 8.82023-07-10
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.
- CVE-2023-30768HIGHCVSS 7.7EG 7.72023-05-12
Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-3095MEDIUMCVSS 6.5EG 6.52023-06-04
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- CVE-2023-3096MEDIUMCVSS 5.3EG 5.32023-06-05
A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been declared as critical. This vulnerability affects the function changedSource. The manipulation leads to improper access controls. An attack has to be a…
- CVE-2023-30969HIGHCVSS 8.2EG 8.22023-10-26
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →