CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 43 of 126
- CVE-2023-3099MEDIUMCVSS 4.4EG 4.42023-06-05
A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function delete_file in the library dbus.SystemBus of the component Arbitrary File Handler. The manipulation l…
- CVE-2023-31019HIGHCVSS 7.8EG 7.82023-11-02
NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to …
- CVE-2023-31020MEDIUMCVSS 6.1EG 6.12023-11-02
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.
- CVE-2023-31100HIGHCVSS 8.4EG 8.42023-11-15
Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: * from 4.3.0.0 before 4.3.0.203 * from 4.3.1.0 befor…
- CVE-2023-31138HIGHCVSS 7.1EG 7.12023-05-09
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, using object model traversal in the payload of a PATCH…
- CVE-2023-3115MEDIUMCVSS 5.4EG 5.42023-09-29
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect projec…
- CVE-2023-31199HIGHCVSS 7.7EG 7.72023-05-12
Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-31241HIGHCVSS 8.6EG 8.62023-05-22
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
- CVE-2023-31242HIGHCVSS 8.1EG 8.12023-09-05
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a…
- CVE-2023-31271HIGHCVSS 6.7EG 7.82024-02-14
Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-31341HIGHCVSS 7.3EG 7.32024-08-13
Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.
- CVE-2023-31346MEDIUMCVSS 6.0EG 6.02024-02-13
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
- CVE-2023-31403CRITICALCVSS 9.6EG 9.62023-11-14
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in th…
- CVE-2023-32009HIGHCVSS 8.8EG 8.82023-06-14
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
- CVE-2023-32060MEDIUMCVSS 6.5EG 6.52023-05-09
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and 2.39.0, when the Category Option Combination Sharing settin…
- CVE-2023-32062MEDIUMCVSS 5.0EG 5.02023-11-27
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability…
- CVE-2023-32063MEDIUMCVSS 5.0EG 5.02023-11-28
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue h…
- CVE-2023-32064MEDIUMCVSS 5.0EG 5.02023-11-28
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security…
- CVE-2023-32065MEDIUMCVSS 5.8EG 5.82023-11-28
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.
- CVE-2023-32204HIGHCVSS 8.8EG 8.82023-11-14
Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-32238MEDIUMCVSS 5.4EG 5.42025-12-30
Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.
- CVE-2023-32279HIGHCVSS 7.5EG 7.52023-11-14
Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthenticated user to potentially enable information disclosure via network access.
- CVE-2023-32285MEDIUMCVSS 6.0EG 6.02023-08-11
Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
- CVE-2023-32333MEDIUMCVSS 6.5EG 6.52024-02-02
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.
- CVE-2023-32458HIGHCVSS 7.3EG 7.32023-09-27
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during…
- CVE-2023-32477HIGHCVSS 7.8EG 7.82023-09-29
Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.
- CVE-2023-32479MEDIUMCVSS 6.7EG 6.72024-02-06
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malic…
- CVE-2023-32544HIGHCVSS 7.3EG 7.32024-01-19
Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-32572MEDIUMCVSS 6.5EG 6.52023-10-03
A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.
- CVE-2023-32609MEDIUMCVSS 5.0EG 5.02023-08-11
Improper access control in the Intel Unite(R) android application before version 4.2.3504 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2023-32632HIGHCVSS 8.8EG 8.82023-10-11
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger th…
- CVE-2023-32647HIGHCVSS 6.8EG 7.82024-02-14
Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-3271HIGHCVSS 8.2EG 8.22023-07-10
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
- CVE-2023-3273HIGHCVSS 7.5EG 7.52023-07-10
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.
- CVE-2023-3303LOWCVSS 3.5EG 3.52023-06-23
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
- CVE-2023-3304MEDIUMCVSS 5.4EG 5.42023-06-23
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
- CVE-2023-3305HIGHCVSS 7.3EG 7.32023-06-18
A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the file /cgi-bin/jumpto.php?class=user&page=config_save&isphp=1 of the component User Creation H…
- CVE-2023-3306HIGHCVSS 7.3EG 7.32023-06-18
A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability affects unknown code of the file app.09df2a9e44ab48766f5f.js of the component Admin Password Handler. The manipulation le…
- CVE-2023-33071HIGHCVSS 8.4EG 8.42023-12-05
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
- CVE-2023-33155HIGHCVSS 7.8EG 7.82023-07-11
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2023-33191MEDIUMCVSS 4.6EG 4.62023-05-30
Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurity `validate.podSecurity` subrule in Kyverno 1.9.2 and 1.9.3 are vulnerable. This issue was patched in version 1.9.4.
- CVE-2023-33301MEDIUMCVSS 6.5EG 6.52023-10-10
An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.
- CVE-2023-33872MEDIUMCVSS 5.5EG 5.52023-11-14
Improper access control in the Intel Support android application all verions may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2023-33875HIGHCVSS 7.1EG 7.12024-02-14
Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..
- CVE-2023-33946LOWCVSS 2.7EG 2.72023-05-24
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objec…
- CVE-2023-33947LOWCVSS 2.7EG 2.72023-05-24
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view obj…
- CVE-2023-3399HIGHCVSS 8.5EG 8.52023-11-06
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or…
- CVE-2023-34106MEDIUMCVSS 6.5EG 6.52023-07-05
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of a…
- CVE-2023-34107MEDIUMCVSS 6.5EG 6.52023-07-05
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all Know…
- CVE-2023-3431MEDIUMCVSS 5.3EG 5.32023-06-27
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →