CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 24 of 126
- CVE-2020-7253MEDIUMCVSS 5.7EG 5.72020-03-12
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.
- CVE-2020-7278HIGHCVSS 7.4EG 7.42020-04-15
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users t…
- CVE-2020-7531HIGHCVSS 7.8EG 7.82020-09-16
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
- CVE-2020-7545HIGHCVSS 7.2EG 7.22020-12-01
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server…
- CVE-2020-7547HIGHCVSS 8.8EG 8.82020-12-01
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via…
- CVE-2020-7561CRITICALCVSS 9.8EG 9.82020-11-19
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution …
- CVE-2020-7573MEDIUMCVSS 6.5EG 6.52020-11-19
A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control.
- CVE-2020-7578HIGHCVSS 8.1EG 8.12020-07-14
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally would not have. This vulnerability could all…
- CVE-2020-8028CRITICALCVSS 9.3EG 9.32020-09-17
A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE Manager Server 3.2, SUSE Manager Server 4…
- CVE-2020-8121HIGHCVSS 8.1EG 8.12020-02-04
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
- CVE-2020-8122MEDIUMCVSS 4.3EG 4.32020-02-04
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
- CVE-2020-8139MEDIUMCVSS 6.5EG 6.52020-03-20
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
- CVE-2020-8153HIGHCVSS 8.1EG 8.12020-05-12
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
- CVE-2020-8157MEDIUMCVSS 6.8EG 6.82020-05-02
UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).
- CVE-2020-8179MEDIUMCVSS 4.1EG 4.12020-07-02
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
- CVE-2020-8182HIGHCVSS 8.0EG 8.02020-10-05
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
- CVE-2020-8193CRITICALCVSS 6.5EG 9.0⚠ KEV2020-07-10
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to cer…
- CVE-2020-8196CRITICALCVSS 4.3EG 9.0⚠ KEV2020-07-10
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information dis…
- CVE-2020-8207HIGHCVSS 8.8EG 8.82020-07-24
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.
- CVE-2020-8275MEDIUMCVSS 4.3EG 4.32021-01-06
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the…
- CVE-2020-8278MEDIUMCVSS 5.3EG 5.32020-11-19
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
- CVE-2020-8300MEDIUMCVSS 6.5EG 6.52021-06-16
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a vali…
- CVE-2020-8902LOWCVSS 3.5EG 3.52021-02-23
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to,…
- CVE-2020-8973CRITICALCVSS 9.3EG 9.32022-10-17
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected asset is located, to operate and change se…
- CVE-2020-9046HIGHCVSS 8.8EG 8.82020-05-26
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
- CVE-2020-9668HIGHCVSS 7.8EG 7.82021-04-16
Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling symbolic links. An unauthenticated attacker could exploit this to elevate privileges in the context of the current user.
- CVE-2020-9754MEDIUMCVSS 5.3EG 5.32022-06-27
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.
- CVE-2021-0205MEDIUMCVSS 5.8EG 5.82021-01-15
When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to bloc…
- CVE-2021-0232HIGHCVSS 7.4EG 7.42021-04-22
An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configurat…
- CVE-2021-1113MEDIUMCVSS 4.7EG 4.72021-08-11
NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauthorized modification to camera resources, which may result in complete denial of service and partial loss of data integr…
- CVE-2021-1228HIGHCVSS 7.4EG 7.42021-02-24
A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to bypass security val…
- CVE-2021-1231MEDIUMCVSS 4.7EG 4.72021-02-24
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-facto…
- CVE-2021-1243HIGHCVSS 5.3EG 7.52021-02-04
A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to allow connections despite the ma…
- CVE-2021-1284HIGHCVSS 8.8EG 8.82021-05-06
A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. …
- CVE-2021-1389MEDIUMCVSS 5.8EG 6.52021-02-04
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for a…
- CVE-2021-1410MEDIUMCVSS 4.3EG 4.32024-11-18
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insu…
- CVE-2021-1419HIGHCVSS 7.8EG 7.82021-09-23
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due t…
- CVE-2021-1449MEDIUMCVSS 6.7EG 6.72021-03-24
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that …
- CVE-2021-1467MEDIUMCVSS 4.3EG 4.32021-04-08
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerabilit…
- CVE-2021-1477MEDIUMCVSS 4.3EG 4.32021-04-29
A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insuf…
- CVE-2021-1478MEDIUMCVSS 5.3EG 5.32021-05-06
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remot…
- CVE-2021-1515MEDIUMCVSS 4.3EG 4.32021-05-06
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage So…
- CVE-2021-1577CRITICALCVSS 9.1EG 9.12021-08-25
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbi…
- CVE-2021-1580HIGHCVSS 6.5EG 7.22021-08-25
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected sys…
- CVE-2021-1581CRITICALCVSS 6.5EG 9.12021-08-25
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected sys…
- CVE-2021-1583MEDIUMCVSS 4.4EG 4.42021-08-25
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an …
- CVE-2021-1591MEDIUMCVSS 5.8EG 5.82021-08-25
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulne…
- CVE-2021-1600HIGHCVSS 8.3EG 8.32021-07-22
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions f…
- CVE-2021-1601HIGHCVSS 8.3EG 8.32021-07-22
Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions f…
- CVE-2021-1625MEDIUMCVSS 5.8EG 5.82021-09-23
A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists beca…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →