CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 57 of 126
- CVE-2024-28967MEDIUMCVSS 5.4EG 5.42024-06-13
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit…
- CVE-2024-28968MEDIUMCVSS 5.4EG 5.42024-06-13
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI). A remote low privileged attacker could pot…
- CVE-2024-28969MEDIUMCVSS 4.3EG 4.32024-06-13
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this…
- CVE-2024-28978MEDIUMCVSS 5.2EG 5.22024-05-01
Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to unauthorized access to resources.
- CVE-2024-29054HIGHCVSS 7.2EG 7.22024-04-09
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- CVE-2024-29055HIGHCVSS 7.2EG 7.22024-04-09
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- CVE-2024-29060MEDIUMCVSS 6.7EG 6.72024-06-11
Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-29077MEDIUMCVSS 6.7EG 6.72024-11-13
Improper access control in some JAM STAPL Player software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-29082HIGHCVSS 8.6EG 8.62024-08-12
Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication and factory res…
- CVE-2024-29085MEDIUMCVSS 5.5EG 5.52024-11-13
Improper access control for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2024-2915HIGHCVSS 8.8EG 8.82024-03-26
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
- CVE-2024-29206LOWCVSS 2.2EG 2.22024-05-07
An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier…
- CVE-2024-29207HIGHCVSS 7.5EG 7.52024-05-07
An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Products: UniFi Connect Application (Version 3.7.9 and earlier) UniFi Connect EV Station (V…
- CVE-2024-29215MEDIUMCVSS 4.3EG 4.32024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that c…
- CVE-2024-29221MEDIUMCVSS 4.7EG 4.72024-04-05
Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the …
- CVE-2024-29836CRITICALCVSS 9.8EG 9.82024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full acce…
- CVE-2024-29837HIGHCVSS 8.8EG 8.82024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
- CVE-2024-29839HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
- CVE-2024-29840HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user
- CVE-2024-29841HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user
- CVE-2024-29842HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any…
- CVE-2024-29843HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels
- CVE-2024-29866CRITICALCVSS 9.1EG 9.12024-03-21
Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.
- CVE-2024-29977LOWCVSS 2.7EG 2.72024-08-01
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts
- CVE-2024-29990CRITICALCVSS 9.0EG 9.02024-04-09
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
- CVE-2024-29993HIGHCVSS 8.8EG 8.82024-04-09
Azure CycleCloud Elevation of Privilege Vulnerability
- CVE-2024-30059MEDIUMCVSS 6.1EG 6.12024-05-14
Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
- CVE-2024-30107LOWCVSS 3.5EG 3.52024-04-18
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.
- CVE-2024-30146MEDIUMCVSS 4.1EG 4.12025-04-30
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.
- CVE-2024-30148MEDIUMCVSS 4.1EG 4.12025-04-24
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
- CVE-2024-30211MEDIUMCVSS 6.0EG 6.02025-02-12
Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-30261LOWCVSS 2.6EG 2.62024-04-04
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patche…
- CVE-2024-30418HIGHCVSS 7.5EG 7.52024-04-07
Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-30481MEDIUMCVSS 6.5EG 6.52024-06-09
Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0.
- CVE-2024-31207MEDIUMCVSS 5.9EG 5.92024-04-04
Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been pat…
- CVE-2024-3127MEDIUMCVSS 4.3EG 4.32024-08-22
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to…
- CVE-2024-31320HIGHCVSS 7.8EG 7.82024-07-09
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges…
- CVE-2024-31503HIGHCVSS 7.5EG 7.52024-04-17
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account take…
- CVE-2024-3164MEDIUMCVSS 4.5EG 4.52024-04-01
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not …
- CVE-2024-31759HIGHCVSS 8.8EG 8.82024-04-16
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
- CVE-2024-31805MEDIUMCVSS 6.5EG 6.52024-04-08
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.
- CVE-2024-31815CRITICALCVSS 9.1EG 9.12024-04-08
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
- CVE-2024-31846HIGHCVSS 7.5EG 7.52024-04-19
An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CVE-2024-31859MEDIUMCVSS 4.3EG 4.32024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin
- CVE-2024-31964HIGHCVSS 7.5EG 7.52024-05-02
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass at…
- CVE-2024-31967CRITICALCVSS 9.1EG 9.12024-05-02
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access atta…
- CVE-2024-32044MEDIUMCVSS 6.8EG 6.82024-11-13
Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2024-32045MEDIUMCVSS 5.9EG 5.92024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channe…
- CVE-2024-32124MEDIUMCVSS 4.3EG 4.32025-07-18
An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request.
- CVE-2024-32418CRITICALCVSS 9.8EG 9.82024-04-22
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →