CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 22 of 126
- CVE-2020-10278MEDIUMCVSS 4.6EG 4.62020-06-24
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.
- CVE-2020-10288CRITICALCVSS 9.8EG 9.82020-07-15
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
- CVE-2020-10612CRITICALCVSS 9.1EG 9.12020-05-14
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with network access to control the SoftPACAg…
- CVE-2020-10627HIGHCVSS 7.3EG 8.12021-12-01
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does no…
- CVE-2020-10641HIGHCVSS 7.5EG 7.52020-04-28
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions…
- CVE-2020-10731CRITICALCVSS 9.9EG 9.92020-07-31
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.
- CVE-2020-10930MEDIUMCVSS 6.5EG 6.52020-07-28
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw ex…
- CVE-2020-11028MEDIUMCVSS 5.8EG 5.82020-04-30
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affecte…
- CVE-2020-11931LOWCVSS 3.3EG 3.32020-05-15
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record vi…
- CVE-2020-12024MEDIUMCVSS 6.1EG 6.12020-06-29
Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB interface from an unauthorized user with physical access. Successful exploitation of this vuln…
- CVE-2020-12030CRITICALCVSS 10.0EG 10.02021-09-29
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports u…
- CVE-2020-12488MEDIUMCVSS 5.5EG 5.52021-11-10
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
- CVE-2020-12493CRITICALCVSS 10.0EG 10.02020-05-29
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device a…
- CVE-2020-13675CRITICALCVSS 9.8EG 9.82022-02-11
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass th…
- CVE-2020-13676MEDIUMCVSS 6.5EG 6.52022-02-11
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installe…
- CVE-2020-13677HIGHCVSS 7.5EG 7.52022-02-11
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
- CVE-2020-14312MEDIUMCVSS 5.9EG 5.92021-02-06
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local s…
- CVE-2020-14388MEDIUMCVSS 6.3EG 6.32021-06-02
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API serv…
- CVE-2020-14499HIGHCVSS 7.5EG 7.52020-07-15
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.
- CVE-2020-14504MEDIUMCVSS 5.3EG 5.32022-02-24
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.
- CVE-2020-15079MEDIUMCVSS 6.4EG 6.42020-07-02
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
- CVE-2020-15102MEDIUMCVSS 6.5EG 6.52020-07-21
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.
- CVE-2020-15181CRITICALCVSS 9.3EG 9.32020-09-18
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is inst…
- CVE-2020-15279MEDIUMCVSS 4.0EG 4.02021-05-18
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during…
- CVE-2020-1604MEDIUMCVSS 6.5EG 6.52020-01-15
On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certain packets to fail. This issue only affects firewall filter evaluation of certain packets …
- CVE-2020-16241MEDIUMCVSS 6.3EG 6.32020-08-21
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CVE-2020-16261MEDIUMCVSS 6.8EG 6.82020-10-28
Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
- CVE-2020-1666MEDIUMCVSS 6.6EG 6.62020-10-16
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access …
- CVE-2020-1732MEDIUMCVSS 4.2EG 4.22020-05-04
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility o…
- CVE-2020-1754MEDIUMCVSS 4.3EG 4.32022-08-05
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
- CVE-2020-2025HIGHCVSS 8.8EG 8.82020-05-19
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers…
- CVE-2020-22655HIGHCVSS 7.5EG 7.52023-01-20
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) befo…
- CVE-2020-24433HIGHCVSS 7.8EG 7.82020-11-05
Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a local privilege escalation vulnerability that could enable a user without administrator privileg…
- CVE-2020-24441MEDIUMCVSS 5.5EG 5.52020-11-12
Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in disclosure of sensitive information stored in databases used by the application…
- CVE-2020-2500CRITICALCVSS 9.8EG 9.82020-07-01
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulner…
- CVE-2020-2504MEDIUMCVSS 5.8EG 5.82020-12-24
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
- CVE-2020-2506CRITICALCVSS 7.3EG 9.8⚠ KEV2021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive i…
- CVE-2020-25160MEDIUMCVSS 6.8EG 6.82022-04-14
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.
- CVE-2020-25238HIGHCVSS 7.8EG 7.82021-02-09
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privile…
- CVE-2020-25629HIGHCVSS 8.8EG 8.82020-12-08
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to …
- CVE-2020-25634MEDIUMCVSS 5.4EG 5.42021-05-26
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.
- CVE-2020-25654HIGHCVSS 7.2EG 7.22020-11-24
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs …
- CVE-2020-25662MEDIUMCVSS 5.3EG 6.52020-11-05
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an ad…
- CVE-2020-25698HIGHCVSS 7.5EG 7.52020-11-19
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.…
- CVE-2020-25701MEDIUMCVSS 5.3EG 5.32020-11-19
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the…
- CVE-2020-26072HIGHCVSS 8.7EG 8.72020-11-18
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient…
- CVE-2020-26077MEDIUMCVSS 4.3EG 4.32020-11-18
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulner…
- CVE-2020-26080MEDIUMCVSS 4.1EG 4.12020-11-18
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability…
- CVE-2020-26224HIGHCVSS 7.5EG 7.52020-11-16
In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function that allows a shopping cart to be recreated from an order already placed. The problem is fix…
- CVE-2020-26942CRITICALCVSS 9.1EG 9.12024-03-21
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin acc…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →