CWE-284— Improper Access Control
4,211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 4 of 85
- CVE-2017-18543CRITICALCVSS 9.8EG 9.82019-08-16
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
- CVE-2017-20066MEDIUMCVSS 5.3EG 7.82022-06-20
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The ex…
- CVE-2017-20199LOWCVSS 3.1EG 3.12025-08-16
A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the component Vault Handler. The manipulation results in improper access controls. The attack ma…
- CVE-2017-20233MEDIUMCVSS 5.4EG 5.42026-04-03
Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured f…
- CVE-2017-2664MEDIUMCVSS 6.5EG 6.52018-07-26
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails applicat…
- CVE-2017-5212CRITICALCVSS 9.8EG 9.82019-05-23
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
- CVE-2017-5863CRITICALCVSS 9.8EG 9.82019-05-22
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- CVE-2017-6912HIGHCVSS 8.8EG 8.82019-05-22
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- CVE-2017-7497MEDIUMCVSS 4.1EG 4.32018-07-27
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
- CVE-2017-7912CRITICALCVSS 9.8EG 9.82019-04-08
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper auth…
- CVE-2017-8340HIGHCVSS 8.8EG 8.82019-05-22
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- CVE-2017-9285MEDIUMCVSS 5.4EG 9.82018-03-02
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
- CVE-2017-9513MEDIUMCVSS 5.4EG 5.42018-01-29
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watc…
- CVE-2017-9626CRITICALCVSS 9.8EG 9.82019-03-27
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.
- CVE-2018-0119MEDIUMCVSS 4.7EG 4.72018-02-08
A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to interact with and view information on an affected device that would normally be prohibited. The vuln…
- CVE-2018-0343HIGHCVSS 8.8EG 8.82018-07-18
A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on a…
- CVE-2018-0428MEDIUMCVSS 6.7EG 6.72018-08-15
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The …
- CVE-2018-0436HIGHCVSS 8.7EG 8.72018-10-05
A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software…
- CVE-2018-0447MEDIUMCVSS 5.3EG 5.32018-10-05
A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device. The vuln…
- CVE-2018-0484MEDIUMCVSS 5.3EG 6.52019-01-10
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in…
- CVE-2018-10500HIGHCVSS 7.0EG 7.02018-09-24
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in…
- CVE-2018-10612CRITICALCVSS 9.8EG 9.82019-01-29
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive info…
- CVE-2018-10630CRITICALCVSS 9.8EG 9.82018-08-10
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When comprom…
- CVE-2018-10631MEDIUMCVSS 6.3EG 6.82018-07-13
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including…
- CVE-2018-1069HIGHCVSS 7.1EG 7.12018-03-09
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesyst…
- CVE-2018-10691HIGHCVSS 7.5EG 7.52019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or…
- CVE-2018-1080HIGHCVSS 7.5EG 8.12018-07-03
Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny r…
- CVE-2018-10905HIGHCVSS 7.8EG 7.82018-07-24
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged use…
- CVE-2018-1129MEDIUMCVSS 6.5EG 6.52018-07-10
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx pr…
- CVE-2018-11456MEDIUMCVSS 5.8EG 5.82018-08-07
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a network port on another …
- CVE-2018-1168HIGHCVSS 7.8EG 7.82018-02-21
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exp…
- CVE-2018-11744HIGHCVSS 8.1EG 8.12019-07-11
Cloudera Manager through 5.15 has Incorrect Access Control.
- CVE-2018-12546MEDIUMCVSS 6.5EG 6.52019-03-27
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in…
- CVE-2018-13816CRITICALCVSS 10.0EG 10.02018-12-12
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attacker to be able to send packets to port 1…
- CVE-2018-13895HIGHCVSS 7.8EG 7.82019-05-24
Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, …
- CVE-2018-13896HIGHCVSS 7.8EG 7.82019-07-22
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage.. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer El…
- CVE-2018-14804CRITICALCVSS 9.8EG 9.82018-10-01
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
- CVE-2018-14833MEDIUMCVSS 5.9EG 5.92019-07-09
Intuit Lacerte 2017 has Incorrect Access Control.
- CVE-2018-14859HIGHCVSS 8.1EG 8.12019-07-03
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure tok…
- CVE-2018-14863HIGHCVSS 8.1EG 8.12019-07-03
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.
- CVE-2018-14864MEDIUMCVSS 6.5EG 6.52019-07-03
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.
- CVE-2018-14867MEDIUMCVSS 5.3EG 5.32019-06-28
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted pa…
- CVE-2018-14885CRITICALCVSS 9.8EG 9.82019-06-28
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary passwor…
- CVE-2018-15371MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability ex…
- CVE-2018-15372HIGHCVSS 8.1EG 8.12018-10-05
A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication…
- CVE-2018-15394CRITICALCVSS 9.8EG 9.82018-11-08
A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affec…
- CVE-2018-15395MEDIUMCVSS 5.4EG 5.42018-10-17
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal cir…
- CVE-2018-15398MEDIUMCVSS 4.0EG 4.02018-10-05
A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) t…
- CVE-2018-15459MEDIUMCVSS 6.5EG 7.22019-01-23
A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device. The vulnerability is due to improper controls on…
- CVE-2018-15466MEDIUMCVSS 5.3EG 3.72019-01-11
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to hav…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →