CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 45 of 126
- CVE-2023-38206MEDIUMCVSS 5.3EG 5.32023-09-14
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnera…
- CVE-2023-38263MEDIUMCVSS 6.5EG 6.52024-02-02
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577.
- CVE-2023-38296HIGHCVSS 8.0EG 8.02024-04-22
Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps…
- CVE-2023-38297HIGHCVSS 8.4EG 8.42024-04-22
An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name …
- CVE-2023-38298HIGHCVSS 8.8EG 8.82024-04-22
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted thir…
- CVE-2023-38411LOWCVSS 3.9EG 3.92023-11-14
Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-38561HIGHCVSS 5.5EG 7.82024-02-14
Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-38848HIGHCVSS 7.5EG 7.52023-10-25
An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
- CVE-2023-38945CRITICALCVSS 9.8EG 9.82024-03-06
Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass the access control and gain complete access to the applicatio…
- CVE-2023-38946HIGHCVSS 8.8EG 8.82024-03-06
An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplying a crafted cookie.
- CVE-2023-3904MEDIUMCVSS 4.3EG 4.32023-12-15
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue t…
- CVE-2023-39221MEDIUMCVSS 5.4EG 5.42023-11-14
Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
- CVE-2023-39228MEDIUMCVSS 5.3EG 5.32023-11-14
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2023-39244HIGHCVSS 7.3EG 7.32024-02-15
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the n…
- CVE-2023-39253HIGHCVSS 7.3EG 7.32023-11-23
Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of …
- CVE-2023-39256HIGHCVSS 7.3EG 7.32023-12-02
Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product …
- CVE-2023-39257HIGHCVSS 7.3EG 7.32023-12-02
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product in…
- CVE-2023-39259HIGHCVSS 7.3EG 7.32023-11-16
Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of …
- CVE-2023-39349HIGHCVSS 8.1EG 8.12023-08-07
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens creat…
- CVE-2023-39376MEDIUMCVSS 6.5EG 6.52023-09-27
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
- CVE-2023-39425HIGHCVSS 8.8EG 8.82024-02-14
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-39432HIGHCVSS 6.7EG 7.82024-02-14
Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-39433MEDIUMCVSS 4.4EG 4.42024-05-16
Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-3964MEDIUMCVSS 4.3EG 4.32023-12-01
An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer pack…
- CVE-2023-39731MEDIUMCVSS 5.3EG 5.32023-10-20
The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- CVE-2023-39743MEDIUMCVSS 5.3EG 5.32023-08-17
lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
- CVE-2023-39941HIGHCVSS 7.1EG 7.12024-02-14
Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- CVE-2023-39952MEDIUMCVSS 6.5EG 6.52023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files inside a subfolder …
- CVE-2023-39959LOWCVSS 3.5EG 3.52023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.9, 26.0.4, and 27.0.1, unauthenticated users could send a DAV request which reveals whether a calend…
- CVE-2023-39961LOWCVSS 3.5EG 3.52023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions…
- CVE-2023-39962HIGHCVSS 7.7EG 7.72023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malici…
- CVE-2023-39963HIGHCVSS 8.1EG 8.12023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password c…
- CVE-2023-39972MEDIUMCVSS 4.3EG 4.32023-08-17
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to create new mailing lists.
- CVE-2023-39973MEDIUMCVSS 4.3EG 4.32023-08-17
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.
- CVE-2023-4002MEDIUMCVSS 6.5EG 6.52023-08-04
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link …
- CVE-2023-40039CRITICALCVSS 9.8EG 9.82023-09-11
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.
- CVE-2023-40060HIGHCVSS 7.2EG 7.22023-09-07
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.…
- CVE-2023-40070HIGHCVSS 8.8EG 8.82024-05-16
Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-40071HIGHCVSS 7.3EG 7.32024-05-16
Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-40161HIGHCVSS 6.6EG 7.82024-02-14
Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-40170MEDIUMCVSS 4.6EG 4.62023-08-28
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab"…
- CVE-2023-4018MEDIUMCVSS 5.3EG 5.32023-09-01
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public proj…
- CVE-2023-40528MEDIUMCVSS 5.5EG 5.52024-01-23
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6.4. An app may be able to bypass Privacy preferences.
- CVE-2023-40573CRITICALCVSS 9.0EG 9.02023-08-24
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming rig…
- CVE-2023-40579MEDIUMCVSS 6.5EG 6.52023-08-25
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affe…
- CVE-2023-40708MEDIUMCVSS 5.8EG 5.82023-08-24
The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.
- CVE-2023-40730HIGHCVSS 7.1EG 8.82023-09-12
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perfor…
- CVE-2023-40850HIGHCVSS 7.5EG 7.52023-09-13
netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the application security gateway.
- CVE-2023-41311MEDIUMCVSS 5.3EG 5.32023-09-27
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
- CVE-2023-41322HIGHCVSS 8.8EG 8.82023-09-27
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can mak…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →