CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,276 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 27 of 126
- CVE-2021-26559MEDIUMCVSS 6.5EG 6.52021-02-17
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `Fa…
- CVE-2021-26627HIGHCVSS 7.5EG 7.52022-04-19
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image.
- CVE-2021-26732MEDIUMCVSS 6.5EG 6.52022-10-24
A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware versio…
- CVE-2021-26733HIGHCVSS 5.3EG 7.52022-10-24
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc…
- CVE-2021-26909MEDIUMCVSS 3.7EG 5.32021-04-23
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in …
- CVE-2021-27258CRITICALCVSS 9.8EG 9.82021-04-14
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Save…
- CVE-2021-27444CRITICALCVSS 9.8EG 9.82022-05-16
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate …
- CVE-2021-27598MEDIUMCVSS 5.3EG 5.32021-04-13
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
- CVE-2021-27653MEDIUMCVSS 6.6EG 6.62021-04-01
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
- CVE-2021-28129HIGHCVSS 7.8EG 7.82021-10-07
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attac…
- CVE-2021-28504HIGHCVSS 7.5EG 7.52022-04-01
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not mat…
- CVE-2021-28505HIGHCVSS 7.5EG 7.52022-04-14
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP proto…
- CVE-2021-28507HIGHCVSS 5.5EG 7.12022-01-14
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agen…
- CVE-2021-28511MEDIUMCVSS 5.8EG 6.52022-08-05
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit actio…
- CVE-2021-28579MEDIUMCVSS 4.3EG 4.32021-06-28
Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event …
- CVE-2021-28798HIGHCVSS 8.8EG 8.82021-05-21
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to modify files that impact system integrity. QNAP have already fixed this vulnerabil…
- CVE-2021-28809CRITICALCVSS 9.8EG 9.82021-07-08
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulner…
- CVE-2021-3062HIGHCVSS 8.1EG 8.82021-11-10
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. …
- CVE-2021-32002MEDIUMCVSS 4.3EG 4.32021-08-05
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions …
- CVE-2021-32514HIGHCVSS 7.5EG 7.52021-07-07
Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3…
- CVE-2021-32517HIGHCVSS 7.5EG 7.52021-07-07
Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular parameter in download function. The referred vulnerability has been solved with the updated ve…
- CVE-2021-32584MEDIUMCVSS 5.3EG 5.32025-03-17
An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker…
- CVE-2021-32652HIGHCVSS 8.8EG 8.82021-06-01
Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1.8.2 contain patche…
- CVE-2021-32656HIGHCVSS 8.6EG 8.62021-06-01
Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, and 21.0.2. An attacker can gain access to basic information about users of a server by acc…
- CVE-2021-32753HIGHCVSS 8.3EG 8.32021-07-09
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is co…
- CVE-2021-33013HIGHCVSS 8.2EG 8.22022-05-13
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
- CVE-2021-33162HIGHCVSS 8.4EG 8.42024-02-23
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-34401HIGHCVSS 7.8EG 7.82022-01-18
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.
- CVE-2021-34402MEDIUMCVSS 6.7EG 6.72022-01-18
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial o…
- CVE-2021-34626MEDIUMCVSS 4.3EG 4.32021-07-07
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
- CVE-2021-34627MEDIUMCVSS 4.3EG 4.32021-07-07
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
- CVE-2021-34696MEDIUMCVSS 5.8EG 5.82021-09-23
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrec…
- CVE-2021-34724MEDIUMCVSS 6.0EG 6.02021-09-23
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on…
- CVE-2021-34753MEDIUMCVSS 5.8EG 5.82024-11-15
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. Thi…
- CVE-2021-34754HIGHCVSS 5.8EG 7.52021-10-27
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffi…
- CVE-2021-34794MEDIUMCVSS 5.3EG 5.32021-10-27
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated,…
- CVE-2021-34795CRITICALCVSS 10.0EG 10.02021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-34864HIGHCVSS 8.8EG 8.82021-10-25
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to…
- CVE-2021-35213HIGHCVSS 8.9EG 8.92021-08-31
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication…
- CVE-2021-35221HIGHCVSS 6.3EG 8.12021-08-31
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
- CVE-2021-35245HIGHCVSS 8.4EG 8.42021-12-06
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
- CVE-2021-35249MEDIUMCVSS 4.3EG 4.32022-05-17
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only …
- CVE-2021-35528HIGHCVSS 7.2EG 7.22021-11-17
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. …
- CVE-2021-3554CRITICALCVSS 9.0EG 10.02021-11-24
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects…
- CVE-2021-36036HIGHCVSS 7.2EG 7.22023-09-06
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the websit…
- CVE-2021-3626HIGHCVSS 8.8EG 8.82021-10-01
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
- CVE-2021-36775HIGHCVSS 8.8EG 8.82022-04-04
a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions pr…
- CVE-2021-36776HIGHCVSS 8.8EG 8.82022-04-04
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.
- CVE-2021-36888CRITICALCVSS 9.8EG 9.82021-12-15
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
- CVE-2021-36909HIGHCVSS 8.8EG 8.82021-11-18
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and ta…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →