CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,502 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 5 of 31
- CVE-2020-9081LOWCVSS 3.5EG 3.52024-12-27
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (V…
- CVE-2021-0260HIGHCVSS 7.3EG 7.32021-04-22
An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauthenticated attacker being able to perform SNMP read actions, an Exposure of System Data to …
- CVE-2021-1574HIGHCVSS 8.8EG 8.82021-07-08
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper autho…
- CVE-2021-1576HIGHCVSS 8.8EG 8.82021-07-08
Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper autho…
- CVE-2021-21026MEDIUMCVSS 5.3EG 5.32021-02-11
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricte…
- CVE-2021-21096MEDIUMCVSS 5.5EG 5.52021-04-15
Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application…
- CVE-2021-21362HIGHCVSS 7.7EG 7.72021-03-08
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a te…
- CVE-2021-21432HIGHCVSS 7.5EG 7.52021-04-09
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials with…
- CVE-2021-21511HIGHCVSS 8.1EG 8.12021-02-15
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain unauthorized read or modification access t…
- CVE-2021-22861MEDIUMCVSS 6.5EG 6.52021-03-03
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write access to unauthorized repositories via specifically crafted pull requests and REST API requ…
- CVE-2021-22862MEDIUMCVSS 6.5EG 6.52021-03-03
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerabil…
- CVE-2021-22863HIGHCVSS 8.1EG 8.12021-03-03
An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authori…
- CVE-2021-22865MEDIUMCVSS 6.5EG 6.52021-04-02
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadata via the REST API without having been g…
- CVE-2021-23136MEDIUMCVSS 6.5EG 6.52021-06-11
Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3);…
- CVE-2021-23140CRITICALCVSS 9.9EG 9.92021-06-11
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR…
- CVE-2021-24188HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPres…
- CVE-2021-24189HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the Word…
- CVE-2021-24190HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress r…
- CVE-2021-24191HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPr…
- CVE-2021-24192HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate…
- CVE-2021-24193HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress reposi…
- CVE-2021-24194HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPre…
- CVE-2021-24195HIGHCVSS 8.8EG 8.82021-05-14
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress r…
- CVE-2021-24311HIGHCVSS 8.8EG 8.82021-06-01
The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.
- CVE-2021-24739HIGHCVSS 8.1EG 8.12021-12-21
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
- CVE-2021-25351LOWCVSS 3.2EG 3.22021-03-25
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
- CVE-2021-25352HIGHCVSS 5.5EG 7.82021-03-25
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
- CVE-2021-25353MEDIUMCVSS 5.5EG 5.52021-03-25
Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the PendingIntent.
- CVE-2021-25354MEDIUMCVSS 3.3EG 5.32021-03-25
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
- CVE-2021-25355MEDIUMCVSS 5.5EG 5.52021-03-25
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
- CVE-2021-25373HIGHCVSS 5.5EG 7.82021-04-09
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action …
- CVE-2021-25374HIGHCVSS 8.6EG 8.62021-04-09
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data relate…
- CVE-2021-25381MEDIUMCVSS 5.5EG 5.52021-04-09
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingInt…
- CVE-2021-25382MEDIUMCVSS 6.1EG 6.12021-04-23
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
- CVE-2021-25399HIGHCVSS 7.1EG 7.12021-06-11
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.
- CVE-2021-25417HIGHCVSS 7.5EG 7.52021-06-11
Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.
- CVE-2021-25433MEDIUMCVSS 5.5EG 5.52021-07-08
Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform factory reset using dbus signal.
- CVE-2021-25459MEDIUMCVSS 4.0EG 5.52021-09-09
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
- CVE-2021-25460MEDIUMCVSS 4.0EG 5.52021-09-09
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
- CVE-2021-25499HIGHCVSS 7.1EG 7.12021-10-06
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.
- CVE-2021-25507MEDIUMCVSS 5.7EG 5.72021-11-05
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.
- CVE-2021-25521MEDIUMCVSS 4.0EG 4.02021-12-08
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
- CVE-2021-25973MEDIUMCVSS 6.5EG 6.52021-11-02
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
- CVE-2021-27663CRITICALCVSS 8.2EG 9.82021-08-30
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3;…
- CVE-2021-27772HIGHCVSS 7.1EG 7.12022-05-12
Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group…
- CVE-2021-28500CRITICALCVSS 9.1EG 9.12022-01-14
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
- CVE-2021-28501CRITICALCVSS 9.1EG 9.12022-01-14
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
- CVE-2021-28506CRITICALCVSS 9.1EG 9.12022-01-14
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
- CVE-2021-28563MEDIUMCVSS 6.5EG 6.52021-06-28
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via the 'Create Customer' endpoint. Successful exploitation could lead to unauthorized modifica…
- CVE-2021-28567MEDIUMCVSS 6.5EG 6.52021-09-08
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify …
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →