CWE-284— Improper Access Control
4,211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 5 of 85
- CVE-2018-15513MEDIUMCVSS 5.3EG 5.32019-08-30
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
- CVE-2018-15610HIGHCVSS 7.3EG 8.82018-09-12
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, a…
- CVE-2018-15611MEDIUMCVSS 6.3EG 6.72018-09-27
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version p…
- CVE-2018-15631MEDIUMCVSS 6.5EG 6.52019-04-09
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.
- CVE-2018-15640HIGHCVSS 8.8EG 8.82019-04-09
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
- CVE-2018-15645MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
- CVE-2018-16466HIGHCVSS 8.1EG 8.12018-10-30
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
- CVE-2018-16476HIGHCVSS 7.5EG 7.52018-11-30
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vu…
- CVE-2018-16553HIGHCVSS 7.2EG 7.22019-06-20
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
- CVE-2018-16838MEDIUMCVSS 5.4EG 5.42019-03-25
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
- CVE-2018-17060MEDIUMCVSS 5.3EG 5.32018-10-08
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
- CVE-2018-17148CRITICALCVSS 9.8EG 9.82019-06-19
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing …
- CVE-2018-17151MEDIUMCVSS 5.4EG 5.42019-07-11
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
- CVE-2018-17559HIGHCVSS 7.5EG 7.52023-10-26
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.
- CVE-2018-17908HIGHCVSS 7.8EG 7.82018-10-29
WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.
- CVE-2018-17921HIGHCVSS 8.8EG 8.82018-10-24
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction.
- CVE-2018-17931MEDIUMCVSS 6.8EG 6.82018-10-30
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to alter scripts, which may allow code execution with root privileges.
- CVE-2018-17953HIGHCVSS 7.5EG 8.12018-11-27
A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).
- CVE-2018-18958MEDIUMCVSS 6.5EG 6.52019-06-17
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
- CVE-2018-19494MEDIUMCVSS 4.3EG 4.32019-07-10
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.
- CVE-2018-19496MEDIUMCVSS 6.5EG 6.52019-07-10
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privi…
- CVE-2018-19576HIGHCVSS 8.1EG 8.12019-07-10
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the iss…
- CVE-2018-19577MEDIUMCVSS 5.3EG 5.32019-07-10
Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential i…
- CVE-2018-19588HIGHCVSS 7.2EG 7.22019-07-11
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
- CVE-2018-19634HIGHCVSS 7.5EG 7.52019-01-22
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.
- CVE-2018-19945CRITICALCVSS 9.1EG 9.12020-12-31
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target syste…
- CVE-2018-20890MEDIUMCVSS 4.3EG 4.32019-08-01
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
- CVE-2018-20930MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
- CVE-2018-20938LOWCVSS 2.7EG 2.72019-08-01
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
- CVE-2018-20957HIGHCVSS 8.8EG 8.82019-08-08
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
- CVE-2018-21007CRITICALCVSS 9.8EG 9.82019-08-29
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
- CVE-2018-25092MEDIUMCVSS 5.5EG 5.52023-11-05
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper …
- CVE-2018-25093MEDIUMCVSS 5.5EG 5.52023-11-06
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgr…
- CVE-2018-3762MEDIUMCVSS 4.3EG 4.32018-07-05
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
- CVE-2018-4844MEDIUMCVSS 6.7EG 6.72018-03-20
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write acce…
- CVE-2018-4845HIGHCVSS 8.8EG 8.82018-06-26
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Sieme…
- CVE-2018-4858HIGHCVSS 7.8EG 7.82018-07-09
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All ver…
- CVE-2018-5264MEDIUMCVSS 5.9EG 5.92019-06-07
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/def…
- CVE-2018-5406HIGHCVSS 8.8EG 8.82019-06-03
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perfor…
- CVE-2018-7362HIGHCVSS 7.5EG 8.82018-11-16
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.
- CVE-2018-7364CRITICALCVSS 9.8EG 9.82018-12-07
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vuln…
- CVE-2018-7520CRITICALCVSS 9.8EG 9.82018-03-22
An improper access control vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which could allow a full configuration download, including passwords.
- CVE-2018-7791CRITICALCVSS 9.8EG 9.82018-08-29
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the origina…
- CVE-2018-7847CRITICALCVSS 9.8EG 9.82019-05-22
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration se…
- CVE-2018-8922MEDIUMCVSS 6.5EG 6.52018-06-01
Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors.
- CVE-2019-0036CRITICALCVSS 9.8EG 9.82019-04-10
When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed withou…
- CVE-2019-0041HIGHCVSS 8.6EG 8.62019-04-10
On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 vers…
- CVE-2019-1010316HIGHCVSS 7.8EG 7.82019-07-11
pyxtrlock 0.3 and earlier is affected by: Incorrect Access Control. The impact is: False locking impression when run in a non-X11 session. The fixed version is: 0.4.
- CVE-2019-10127HIGHCVSS 8.8EG 8.82021-03-19
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inheri…
- CVE-2019-10128HIGHCVSS 7.8EG 7.82021-03-19
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the …
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →