CWE-284— Improper Access Control
4,211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 8 of 85
- CVE-2019-6140CRITICALCVSS 9.8EG 9.82019-04-09
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not completed.
- CVE-2019-6144MEDIUMCVSS 6.5EG 6.52019-10-23
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.
- CVE-2019-6193HIGHCVSS 7.5EG 7.52020-02-14
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresse…
- CVE-2019-6517MEDIUMCVSS 6.8EG 6.82019-02-06
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Professional Operating System US release does not properly enfor…
- CVE-2019-6520HIGHCVSS 7.5EG 7.52019-03-05
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.
- CVE-2019-6538CRITICALCVSS 9.3EG 6.52019-03-25
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Co…
- CVE-2019-6544MEDIUMCVSS 5.6EG 5.62019-05-09
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system admi…
- CVE-2019-6554HIGHCVSS 7.5EG 7.52019-04-05
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.
- CVE-2019-6566HIGHCVSS 7.8EG 7.82019-05-09
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system.
- CVE-2019-6744MEDIUMCVSS 4.3EG 4.32020-02-10
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the de…
- CVE-2019-6810HIGHCVSS 8.8EG 8.82019-09-17
CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol.
- CVE-2019-7475CRITICALCVSS 9.8EG 9.82019-04-02
A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced routing services. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier,…
- CVE-2019-7476HIGHCVSS 8.1EG 8.12019-04-26
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.
- CVE-2019-7611HIGHCVSS 8.1EG 8.12019-03-25
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and the _aliases, _shrink, or _split endpoints are used . If the elasticsearch.yml file has x…
- CVE-2019-8456MEDIUMCVSS 5.9EG 5.92019-04-09
Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.
- CVE-2019-9529MEDIUMCVSS 5.5EG 5.52019-10-10
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the …
- CVE-2019-9530MEDIUMCVSS 5.5EG 5.52019-10-10
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could allow an unauthenticated, local attacker connected to the device to access and download a…
- CVE-2019-9531CRITICALCVSS 9.8EG 9.82019-10-10
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT)…
- CVE-2019-9884CRITICALCVSS 9.8EG 9.82019-07-25
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.
- CVE-2019-9886HIGHCVSS 7.5EG 7.52019-07-11
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.
- CVE-2020-10138HIGHCVSS 7.8EG 7.82020-10-21
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses thi…
- CVE-2020-10139HIGHCVSS 7.8EG 7.82020-10-21
Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True Image contains a privileged service that uses this OpenSSL component. Because unprivileged…
- CVE-2020-10143HIGHCVSS 7.8EG 7.82020-12-09
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectorie…
- CVE-2020-10145HIGHCVSS 7.8EG 7.82021-05-27
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a …
- CVE-2020-10278MEDIUMCVSS 4.6EG 4.62020-06-24
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.
- CVE-2020-10288CRITICALCVSS 9.8EG 9.82020-07-15
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
- CVE-2020-10612CRITICALCVSS 9.1EG 9.12020-05-14
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with network access to control the SoftPACAg…
- CVE-2020-10627HIGHCVSS 7.3EG 8.12021-12-01
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does no…
- CVE-2020-10641HIGHCVSS 7.5EG 7.52020-04-28
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions…
- CVE-2020-10731CRITICALCVSS 9.9EG 9.92020-07-31
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.
- CVE-2020-10930MEDIUMCVSS 6.5EG 6.52020-07-28
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw ex…
- CVE-2020-11028MEDIUMCVSS 5.8EG 5.82020-04-30
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affecte…
- CVE-2020-11931LOWCVSS 3.3EG 3.32020-05-15
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record vi…
- CVE-2020-12024MEDIUMCVSS 6.1EG 6.12020-06-29
Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB interface from an unauthorized user with physical access. Successful exploitation of this vuln…
- CVE-2020-12030CRITICALCVSS 10.0EG 10.02021-09-29
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports u…
- CVE-2020-12488MEDIUMCVSS 5.5EG 5.52021-11-10
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
- CVE-2020-12493CRITICALCVSS 10.0EG 10.02020-05-29
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device a…
- CVE-2020-13675CRITICALCVSS 9.8EG 9.82022-02-11
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass th…
- CVE-2020-13676MEDIUMCVSS 6.5EG 6.52022-02-11
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installe…
- CVE-2020-13677HIGHCVSS 7.5EG 7.52022-02-11
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
- CVE-2020-14312MEDIUMCVSS 5.9EG 5.92021-02-06
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local s…
- CVE-2020-14388MEDIUMCVSS 6.3EG 6.32021-06-02
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API serv…
- CVE-2020-14499HIGHCVSS 7.5EG 7.52020-07-15
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.
- CVE-2020-14504MEDIUMCVSS 5.3EG 5.32022-02-24
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.
- CVE-2020-15079MEDIUMCVSS 6.4EG 6.42020-07-02
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
- CVE-2020-15102MEDIUMCVSS 6.5EG 6.52020-07-21
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.
- CVE-2020-15181CRITICALCVSS 9.3EG 9.32020-09-18
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is inst…
- CVE-2020-15279MEDIUMCVSS 4.0EG 3.32021-05-18
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during…
- CVE-2020-1604MEDIUMCVSS 6.5EG 6.52020-01-15
On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certain packets to fail. This issue only affects firewall filter evaluation of certain packets …
- CVE-2020-16241MEDIUMCVSS 6.3EG 2.12020-08-21
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →