CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 18 of 126
- CVE-2018-1069HIGHCVSS 7.1EG 7.12018-03-09
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesyst…
- CVE-2018-10691HIGHCVSS 7.5EG 7.52019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or…
- CVE-2018-1080HIGHCVSS 7.5EG 8.12018-07-03
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny r…
- CVE-2018-10905HIGHCVSS 7.8EG 7.82018-07-24
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged use…
- CVE-2018-1129MEDIUMCVSS 6.5EG 6.52018-07-10
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx pr…
- CVE-2018-11456MEDIUMCVSS 5.8EG 5.82018-08-07
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a network port on another …
- CVE-2018-1168HIGHCVSS 7.8EG 7.82018-02-21
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exp…
- CVE-2018-11744HIGHCVSS 8.1EG 8.12019-07-11
Cloudera Manager through 5.15 has Incorrect Access Control.
- CVE-2018-12546MEDIUMCVSS 6.5EG 6.52019-03-27
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in…
- CVE-2018-13816CRITICALCVSS 10.0EG 10.02018-12-12
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attacker to be able to send packets to port 1…
- CVE-2018-13895HIGHCVSS 7.8EG 7.82019-05-24
Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, …
- CVE-2018-13896HIGHCVSS 7.8EG 7.82019-07-22
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage.. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer El…
- CVE-2018-14804CRITICALCVSS 9.8EG 9.82018-10-01
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
- CVE-2018-14833MEDIUMCVSS 5.9EG 5.92019-07-09
Intuit Lacerte 2017 has Incorrect Access Control.
- CVE-2018-14859HIGHCVSS 8.1EG 8.12019-07-03
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure tok…
- CVE-2018-14863HIGHCVSS 8.1EG 8.12019-07-03
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.
- CVE-2018-14864MEDIUMCVSS 6.5EG 6.52019-07-03
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.
- CVE-2018-14867MEDIUMCVSS 5.3EG 5.32019-06-28
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted pa…
- CVE-2018-14885CRITICALCVSS 9.8EG 9.82019-06-28
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary passwor…
- CVE-2018-15371MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability ex…
- CVE-2018-15372HIGHCVSS 8.1EG 8.12018-10-05
A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication…
- CVE-2018-15394CRITICALCVSS 9.8EG 9.82018-11-08
A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affec…
- CVE-2018-15395MEDIUMCVSS 5.4EG 5.42018-10-17
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal cir…
- CVE-2018-15398MEDIUMCVSS 4.0EG 4.02018-10-05
A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) t…
- CVE-2018-15459HIGHCVSS 6.5EG 7.22019-01-23
A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device. The vulnerability is due to improper controls on…
- CVE-2018-15466MEDIUMCVSS 5.3EG 5.32019-01-11
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to hav…
- CVE-2018-15513MEDIUMCVSS 5.3EG 5.32019-08-30
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
- CVE-2018-15610HIGHCVSS 7.3EG 8.82018-09-12
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, a…
- CVE-2018-15611MEDIUMCVSS 6.3EG 6.72018-09-27
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version p…
- CVE-2018-15631MEDIUMCVSS 6.5EG 6.52019-04-09
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.
- CVE-2018-15640HIGHCVSS 8.8EG 8.82019-04-09
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
- CVE-2018-15645MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
- CVE-2018-16466HIGHCVSS 8.1EG 8.12018-10-30
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
- CVE-2018-16476HIGHCVSS 7.5EG 7.52018-11-30
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vu…
- CVE-2018-16553HIGHCVSS 7.2EG 7.22019-06-20
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
- CVE-2018-16838MEDIUMCVSS 5.4EG 5.42019-03-25
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
- CVE-2018-17060MEDIUMCVSS 5.3EG 5.32018-10-08
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
- CVE-2018-17148CRITICALCVSS 9.8EG 9.82019-06-19
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing …
- CVE-2018-17151MEDIUMCVSS 5.4EG 5.42019-07-11
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
- CVE-2018-17559HIGHCVSS 7.5EG 7.52023-10-26
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.
- CVE-2018-17908HIGHCVSS 7.8EG 7.82018-10-29
WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.
- CVE-2018-17921HIGHCVSS 8.8EG 8.82018-10-24
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction.
- CVE-2018-17931MEDIUMCVSS 6.8EG 6.82018-10-30
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to alter scripts, which may allow code execution with root privileges.
- CVE-2018-17953HIGHCVSS 7.5EG 8.12018-11-27
A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).
- CVE-2018-18958MEDIUMCVSS 6.5EG 6.52019-06-17
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
- CVE-2018-19494MEDIUMCVSS 4.3EG 4.32019-07-10
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.
- CVE-2018-19496MEDIUMCVSS 6.5EG 6.52019-07-10
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privi…
- CVE-2018-19576HIGHCVSS 8.1EG 8.12019-07-10
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the iss…
- CVE-2018-19577MEDIUMCVSS 5.3EG 5.32019-07-10
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential i…
- CVE-2018-19588HIGHCVSS 7.2EG 7.22019-07-11
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →