CWE-284— Improper Access Control
4,211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 11 of 85
- CVE-2020-9754MEDIUMCVSS 5.3EG 5.32022-06-27
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.
- CVE-2021-0205MEDIUMCVSS 5.8EG 5.82021-01-15
When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to bloc…
- CVE-2021-0232HIGHCVSS 7.4EG 7.42021-04-22
An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configurat…
- CVE-2021-1113MEDIUMCVSS 4.7EG 4.72021-08-11
NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauthorized modification to camera resources, which may result in complete denial of service and partial loss of data integr…
- CVE-2021-1228HIGHCVSS 7.4EG 6.52021-02-24
A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to bypass security val…
- CVE-2021-1231MEDIUMCVSS 4.7EG 4.72021-02-24
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-facto…
- CVE-2021-1243MEDIUMCVSS 5.3EG 7.52021-02-04
A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to allow connections despite the ma…
- CVE-2021-1284HIGHCVSS 8.8EG 8.82021-05-06
A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. …
- CVE-2021-1389MEDIUMCVSS 5.8EG 6.52021-02-04
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for a…
- CVE-2021-1410MEDIUMCVSS 4.3EG 4.32024-11-18
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insu…
- CVE-2021-1419HIGHCVSS 7.8EG 7.82021-09-23
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due t…
- CVE-2021-1449MEDIUMCVSS 6.7EG 6.72021-03-24
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that …
- CVE-2021-1467MEDIUMCVSS 4.3EG 4.32021-04-08
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerabilit…
- CVE-2021-1477MEDIUMCVSS 4.3EG 4.32021-04-29
A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insuf…
- CVE-2021-1478MEDIUMCVSS 5.3EG 5.32021-05-06
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remot…
- CVE-2021-1515MEDIUMCVSS 4.3EG 4.32021-05-06
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage So…
- CVE-2021-1577CRITICALCVSS 9.1EG 9.12021-08-25
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbi…
- CVE-2021-1580MEDIUMCVSS 6.5EG 7.22021-08-25
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected sys…
- CVE-2021-1581MEDIUMCVSS 6.5EG 9.12021-08-25
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected sys…
- CVE-2021-1583MEDIUMCVSS 4.4EG 4.42021-08-25
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an …
- CVE-2021-1591MEDIUMCVSS 5.8EG 5.32021-08-25
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulne…
- CVE-2021-1600HIGHCVSS 8.3EG 8.32021-07-22
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions f…
- CVE-2021-1601HIGHCVSS 8.3EG 8.32021-07-22
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions f…
- CVE-2021-1625MEDIUMCVSS 5.8EG 5.82021-09-23
A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists beca…
- CVE-2021-20034CRITICALCVSS 9.1EG 9.12021-09-27
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
- CVE-2021-20050HIGHCVSS 7.5EG 7.52021-12-23
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
- CVE-2021-21020MEDIUMCVSS 5.3EG 5.32021-02-11
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the Login as Customer module. Successful exploitation could lead to unauthorized access to res…
- CVE-2021-21045HIGHCVSS 8.2EG 8.22021-02-11
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper access control vulnerability. An unauthenticated attacker could leverage this vulne…
- CVE-2021-21083HIGHCVSS 7.5EG 7.52021-06-28
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacker could leverage this vulnerability to c…
- CVE-2021-21399CRITICALCVSS 9.1EG 9.12021-04-13
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of …
- CVE-2021-21425CRITICALCVSS 9.3EG 9.32021-04-07
Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any…
- CVE-2021-21431HIGHCVSS 7.6EG 7.62021-04-09
sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once. We also …
- CVE-2021-21703HIGHCVSS 7.8EG 7.02021-10-25
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possibl…
- CVE-2021-21964HIGHCVSS 7.4EG 7.52022-02-04
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet …
- CVE-2021-21965CRITICALCVSS 9.3EG 8.22022-02-04
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious …
- CVE-2021-22126MEDIUMCVSS 6.7EG 6.72025-03-17
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru …
- CVE-2021-22565MEDIUMCVSS 6.5EG 6.52021-12-09
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1…
- CVE-2021-22567MEDIUMCVSS 4.6EG 4.62022-01-05
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible…
- CVE-2021-22682HIGHCVSS 7.8EG 7.82021-04-23
Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write access. This may allow unprivileged users to modify the binaries and configuration files an…
- CVE-2021-22853MEDIUMCVSS 5.4EG 5.42021-02-17
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not t…
- CVE-2021-22877MEDIUMCVSS 6.5EG 6.52021-03-03
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
- CVE-2021-22907HIGHCVSS 7.8EG 7.82021-05-27
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.
- CVE-2021-22920MEDIUMCVSS 6.5EG 6.52021-08-05
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilit…
- CVE-2021-22941CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-23
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
- CVE-2021-23173LOWCVSS 2.6EG 4.32022-01-10
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
- CVE-2021-23176MEDIUMCVSS 6.5EG 6.52023-04-25
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.
- CVE-2021-23178HIGHCVSS 7.5EG 7.52023-04-25
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method …
- CVE-2021-23203HIGHCVSS 7.5EG 7.52023-04-25
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
- CVE-2021-23233HIGHCVSS 7.3EG 7.32022-01-21
Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform…
- CVE-2021-23845HIGHCVSS 8.0EG 8.02021-06-18
This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →