CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 17 of 126
- CVE-2017-12171MEDIUMCVSS 6.5EG 6.52018-07-26
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to a…
- CVE-2017-12191HIGHCVSS 7.4EG 7.42018-02-28
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and …
- CVE-2017-12262HIGHCVSS 8.8EG 8.82017-11-02
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available …
- CVE-2017-12340MEDIUMCVSS 4.2EG 4.22017-11-30
A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell …
- CVE-2017-14031HIGHCVSS 7.8EG 7.82017-11-06
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the target machine.
- CVE-2017-15131HIGHCVSS 7.8EG 7.82018-01-09
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enter…
- CVE-2017-15891MEDIUMCVSS 6.5EG 6.52017-12-08
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
- CVE-2017-16766MEDIUMCVSS 6.5EG 6.52017-12-22
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
- CVE-2017-18035MEDIUMCVSS 4.3EG 4.32018-02-02
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular…
- CVE-2017-18101MEDIUMCVSS 6.5EG 6.52018-04-10
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow re…
- CVE-2017-18380HIGHCVSS 7.5EG 7.52019-07-30
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
- CVE-2017-18384LOWCVSS 3.8EG 3.82019-08-02
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
- CVE-2017-18385MEDIUMCVSS 5.5EG 5.52019-08-02
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
- CVE-2017-18403MEDIUMCVSS 6.3EG 6.32019-08-02
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
- CVE-2017-18404LOWCVSS 3.1EG 3.12019-08-02
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
- CVE-2017-18416MEDIUMCVSS 5.5EG 5.52019-08-02
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
- CVE-2017-18421LOWCVSS 3.3EG 3.32019-08-02
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
- CVE-2017-18457MEDIUMCVSS 4.4EG 4.42019-08-02
cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
- CVE-2017-18543CRITICALCVSS 9.8EG 9.82019-08-16
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
- CVE-2017-20066HIGHCVSS 5.3EG 7.82022-06-20
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The ex…
- CVE-2017-20199LOWCVSS 3.1EG 3.12025-08-16
A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the component Vault Handler. The manipulation results in improper access controls. The attack ma…
- CVE-2017-20233MEDIUMCVSS 5.4EG 5.42026-04-03
Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured f…
- CVE-2017-2664MEDIUMCVSS 6.5EG 6.52018-07-26
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails applicat…
- CVE-2017-5212CRITICALCVSS 9.8EG 9.82019-05-23
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
- CVE-2017-5254HIGHCVSS 8.8EG 8.92017-12-20
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechani…
- CVE-2017-5863CRITICALCVSS 9.8EG 9.82019-05-22
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- CVE-2017-6016HIGHCVSS 7.3EG 7.32017-05-19
An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions are affected: Versions 4.1 and prior versions released before January 20, 2017. An Improp…
- CVE-2017-6866MEDIUMCVSS 6.5EG 6.52017-08-07
A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileged remote user to gain read access to data in the XHQ solution exceeding his configured pe…
- CVE-2017-6912HIGHCVSS 8.8EG 8.82019-05-22
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- CVE-2017-7497MEDIUMCVSS 4.1EG 4.32018-07-27
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
- CVE-2017-7912CRITICALCVSS 9.8EG 9.82019-04-08
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper auth…
- CVE-2017-7918MEDIUMCVSS 6.8EG 6.82017-06-21
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack p…
- CVE-2017-7928CRITICALCVSS 10.0EG 10.02017-08-07
An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1. The device does not properly enforce access c…
- CVE-2017-8340HIGHCVSS 8.8EG 8.82019-05-22
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- CVE-2017-8438HIGHCVSS 8.8EG 8.82017-06-05
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been created using a templ…
- CVE-2017-8447MEDIUMCVSS 6.5EG 6.52017-09-29
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.
- CVE-2017-8448HIGHCVSS 8.8EG 8.82017-09-29
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.
- CVE-2017-9285CRITICALCVSS 5.4EG 9.82018-03-02
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
- CVE-2017-9513MEDIUMCVSS 5.4EG 5.42018-01-29
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watc…
- CVE-2017-9626CRITICALCVSS 9.8EG 9.82019-03-27
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.
- CVE-2018-0119MEDIUMCVSS 4.7EG 4.72018-02-08
A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to interact with and view information on an affected device that would normally be prohibited. The vuln…
- CVE-2018-0343HIGHCVSS 8.8EG 8.82018-07-18
A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on a…
- CVE-2018-0428MEDIUMCVSS 6.7EG 6.72018-08-15
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The …
- CVE-2018-0436HIGHCVSS 8.7EG 8.72018-10-05
A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software…
- CVE-2018-0447MEDIUMCVSS 5.3EG 5.32018-10-05
A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device. The vuln…
- CVE-2018-0484MEDIUMCVSS 5.3EG 6.52019-01-10
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in…
- CVE-2018-10500HIGHCVSS 7.0EG 7.02018-09-24
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in…
- CVE-2018-10612CRITICALCVSS 9.8EG 9.82019-01-29
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive info…
- CVE-2018-10630CRITICALCVSS 9.8EG 9.82018-08-10
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When comprom…
- CVE-2018-10631MEDIUMCVSS 6.3EG 6.82018-07-13
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →