CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 46 of 126
- CVE-2023-41570MEDIUMCVSS 5.3EG 5.32023-11-14
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
- CVE-2023-41603MEDIUMCVSS 5.3EG 5.32024-01-10
D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.
- CVE-2023-41679CRITICALCVSS 9.6EG 9.62023-10-10
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with a…
- CVE-2023-4169HIGHCVSS 8.8EG 8.92023-08-05
A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_passwd of the component Administrator Password Handler. The ma…
- CVE-2023-41721CRITICALCVSS 5.3EG 10.02023-10-25
Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration…
- CVE-2023-41772HIGHCVSS 7.8EG 7.82023-10-10
Win32k Elevation of Privilege Vulnerability
- CVE-2023-4183CRITICALCVSS 9.8EG 9.82023-08-06
A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the …
- CVE-2023-41882MEDIUMCVSS 4.3EG 4.32023-10-11
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaborati…
- CVE-2023-4227MEDIUMCVSS 6.5EG 6.52023-08-24
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security…
- CVE-2023-42481HIGHCVSS 8.1EG 8.12023-12-12
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP…
- CVE-2023-42540MEDIUMCVSS 5.5EG 5.52023-11-07
Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.
- CVE-2023-42542LOWCVSS 3.3EG 3.32023-11-07
Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.
- CVE-2023-42769CRITICALCVSS 9.8EG 9.82023-10-26
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
- CVE-2023-42838HIGHCVSS 8.6EG 8.62024-02-21
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated…
- CVE-2023-42853MEDIUMCVSS 5.5EG 5.52024-02-21
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to access user-sensitive data.
- CVE-2023-42859HIGHCVSS 5.5EG 7.72024-02-21
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.
- CVE-2023-42860HIGHCVSS 5.5EG 7.72024-02-21
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.
- CVE-2023-42945CRITICALCVSS 5.5EG 9.12024-02-21
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Bluetooth.
- CVE-2023-42957LOWCVSS 3.3EG 3.32024-07-29
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.
- CVE-2023-42969LOWCVSS 3.3EG 3.32025-04-11
An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. The issue was addressed with improved handling of caches.
- CVE-2023-43072HIGHCVSS 7.8EG 7.82023-10-05
Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbri…
- CVE-2023-43079HIGHCVSS 7.8EG 7.82023-10-13
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to…
- CVE-2023-43086HIGHCVSS 7.8EG 7.82023-11-23
Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modify files inside installation folder during application upgrade, leading to privilege escal…
- CVE-2023-43089MEDIUMCVSS 3.3EG 4.42023-12-01
Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to un…
- CVE-2023-43119CRITICALCVSS 9.8EG 9.82023-10-16
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
- CVE-2023-43141CRITICALCVSS 9.8EG 9.82023-09-25
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
- CVE-2023-4317MEDIUMCVSS 4.3EG 4.32023-12-01
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a user with the Developer role…
- CVE-2023-43318HIGHCVSS 8.8EG 8.82024-03-06
TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
- CVE-2023-43336HIGHCVSS 8.8EG 8.82023-11-02
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
- CVE-2023-43487MEDIUMCVSS 4.7EG 4.72024-05-16
Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-43489MEDIUMCVSS 5.5EG 5.52024-08-14
Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-43491MEDIUMCVSS 5.3EG 5.32024-04-17
An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An atta…
- CVE-2023-43505CRITICALCVSS 6.5EG 9.62023-11-14
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
- CVE-2023-43517HIGHCVSS 8.4EG 8.42024-02-06
Memory corruption in Automotive Multimedia due to improper access control in HAB.
- CVE-2023-43585HIGHCVSS 6.5EG 7.12023-12-13
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
- CVE-2023-43626HIGHCVSS 7.5EG 7.52024-09-16
Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-43696CRITICALCVSS 9.8EG 9.82023-10-09
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
- CVE-2023-43748HIGHCVSS 7.8EG 7.82024-05-16
Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-4379HIGHCVSS 7.5EG 8.12023-11-09
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
- CVE-2023-43814LOWCVSS 3.7EG 3.72023-10-16
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for g…
- CVE-2023-43847MEDIUMCVSS 5.3EG 5.32024-05-28
Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to control all the outlets as if they were the administrator via HTTP POST requests.
- CVE-2023-43848HIGHCVSS 8.0EG 8.02024-05-28
Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall settings of the device as if they were the administrator via HTTP PO…
- CVE-2023-43849MEDIUMCVSS 6.5EG 6.52024-05-28
Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image via HTTP POST requests. This may result in DoS or remote code execution.
- CVE-2023-43901MEDIUMCVSS 5.9EG 5.92023-11-14
Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.
- CVE-2023-44031HIGHCVSS 7.5EG 7.52024-02-03
Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request.
- CVE-2023-44118CRITICALCVSS 9.1EG 9.12023-10-11
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
- CVE-2023-44248MEDIUMCVSS 5.5EG 5.52023-11-14
An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by t…
- CVE-2023-44282HIGHCVSS 7.8EG 7.82023-11-16
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.…
- CVE-2023-44283HIGHCVSS 7.8EG 7.82024-02-14
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue …
- CVE-2023-44289HIGHCVSS 7.8EG 7.82023-11-23
Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege …
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →