CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 33 of 126
- CVE-2022-32946MEDIUMCVSS 5.5EG 5.52022-11-01
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.
- CVE-2022-33243HIGHCVSS 8.4EG 8.42023-02-12
Memory corruption due to improper access control in Qualcomm IPC.
- CVE-2022-3325MEDIUMCVSS 2.7EG 4.32022-10-17
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules v…
- CVE-2022-3369HIGHCVSS 8.6EG 8.62022-11-01
An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete privileged registry keys by pointing a Registry symlink to a privileged key. This issue a…
- CVE-2022-33701LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
- CVE-2022-33706LOWCVSS 2.4EG 2.42022-07-12
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.
- CVE-2022-33714MEDIUMCVSS 6.2EG 6.22022-08-05
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
- CVE-2022-33720LOWCVSS 2.4EG 2.42022-08-05
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
- CVE-2022-33731HIGHCVSS 5.1EG 7.12022-08-05
Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.
- CVE-2022-33757MEDIUMCVSS 6.5EG 6.52022-10-25
An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of information on the scan target and/or the Nessus scan to unauthorized…
- CVE-2022-3382HIGHCVSS 7.5EG 7.52022-10-17
HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the controller and cause a denial-of-service condition.
- CVE-2022-33924MEDIUMCVSS 4.3EG 5.32022-08-10
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules could potentially exploit this vulnerability and create rules.
- CVE-2022-33925MEDIUMCVSS 6.5EG 6.52022-08-10
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports con…
- CVE-2022-33926HIGHCVSS 7.1EG 7.12022-08-10
Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.
- CVE-2022-33931MEDIUMCVSS 6.3EG 6.32022-08-10
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to Alert Classification page could potentially exploit this vulnerability, leading to the change the alert categ…
- CVE-2022-34255HIGHCVSS 8.8EG 8.82022-08-16
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account cou…
- CVE-2022-34259MEDIUMCVSS 5.3EG 5.32022-08-16
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnera…
- CVE-2022-34270CRITICALCVSS 9.8EG 9.82024-02-29
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
- CVE-2022-3436HIGHCVSS 6.3EG 7.52022-10-09
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Photo Handler. The manipulati…
- CVE-2022-34431MEDIUMCVSS 6.5EG 6.52022-10-11
Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker could potentially exploit this vulnerability, leading to DHC system not being accessible.
- CVE-2022-34453HIGHCVSS 7.6EG 7.62023-08-03
Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.
- CVE-2022-34457HIGHCVSS 7.3EG 7.82023-01-18
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows no…
- CVE-2022-3458CRITICALCVSS 6.3EG 9.82022-10-12
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler.…
- CVE-2022-34672HIGHCVSS 7.8EG 7.82022-12-30
NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or executing commands.
- CVE-2022-34827CRITICALCVSS 9.9EG 9.92022-11-18
Carel Boss Mini 1.5.0 has Improper Access Control.
- CVE-2022-34894MEDIUMCVSS 3.5EG 5.32022-07-01
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
- CVE-2022-3496HIGHCVSS 6.3EG 8.82022-10-14
A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical. This issue affects some unknown processing of the file employeeadd.php of the component Admin Panel. The manipulation leads to imp…
- CVE-2022-35276HIGHCVSS 7.5EG 7.52022-11-11
Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-35621MEDIUMCVSS 5.3EG 5.32022-09-21
Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e6a9a2d7f1510a00d898737b05f48ae allows remote attackers to execute fraudulent NFT transfers.
- CVE-2022-35689MEDIUMCVSS 5.3EG 5.32022-10-14
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the ava…
- CVE-2022-35843CRITICALCVSS 8.1EG 9.82022-12-06
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 th…
- CVE-2022-36024HIGHCVSS 7.5EG 7.52022-08-18
py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` scope without the `bot` scope. Currently…
- CVE-2022-36088MEDIUMCVSS 5.0EG 5.02022-09-07
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malic…
- CVE-2022-36263HIGHCVSS 7.3EG 7.32022-08-19
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.
- CVE-2022-36374HIGHCVSS 7.5EG 7.52023-11-14
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-36385MEDIUMCVSS 6.8EG 6.82022-09-13
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat acto…
- CVE-2022-36396HIGHCVSS 8.2EG 8.22023-11-14
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-36441HIGHCVSS 7.1EG 7.12023-01-10
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other applications that are restricted by the admin.
- CVE-2022-36442MEDIUMCVSS 5.5EG 5.52023-01-10
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK.
- CVE-2022-36443HIGHCVSS 7.8EG 7.82023-01-10
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without r…
- CVE-2022-36771MEDIUMCVSS 6.5EG 6.52022-09-28
IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.
- CVE-2022-36789HIGHCVSS 7.5EG 7.82022-11-11
Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local ac…
- CVE-2022-36832MEDIUMCVSS 4.0EG 4.02022-08-05
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.
- CVE-2022-36851MEDIUMCVSS 3.9EG 4.62022-09-09
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
- CVE-2022-36856MEDIUMCVSS 4.0EG 4.02022-09-09
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.
- CVE-2022-36864HIGHCVSS 4.0EG 7.82022-09-09
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.
- CVE-2022-36865MEDIUMCVSS 4.0EG 4.02022-09-09
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.
- CVE-2022-36866MEDIUMCVSS 4.0EG 4.02022-09-09
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
- CVE-2022-36867MEDIUMCVSS 5.9EG 5.92022-09-09
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.
- CVE-2022-36869MEDIUMCVSS 6.6EG 6.62022-09-09
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →