← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Devolutions
1Remote Desktop Manager
Nov 21, 2024
Sep 13, 2022
N/A· v4
7.0 HIGH· v3
N/A· v2
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop...Show more
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.Show less
1Contechealth
1Cms8000 Firmware
Nov 21, 2024
Sep 13, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attem...Show more
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.Show less
1Contechealth
1Cms8000 Firmware
Nov 21, 2024
Sep 13, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to pr...Show more
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.Show less
1Siemens
1Coreshield One Way Gateway
Nov 21, 2024
Sep 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to...Show more
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.Show less
1Samsung
1Galaxy Watch Plugin
Nov 21, 2024
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
1Samsung
1Contacts Provider
Nov 21, 2024
Sep 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.
1Samsung
1Editor Lite
Nov 21, 2024
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.
1Samsung
1Group Sharing
Nov 21, 2024
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
1Samsung
1Group Sharing
Nov 21, 2024
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.
1Samsung
1Samsung Email
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.
1Google
1Android
Nov 21, 2024
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.
1Samsung
1Samsung Pass
Nov 21, 2024
Sep 9, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
1Cisco
2Catalyst Sd Wan Manager
Sd Wan Vmanage
Nov 21, 2024
Sep 8, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service p...Show more
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnerability exists because the messaging server container ports on an affected system lack sufficient protection mechanisms. An attacker could exploit this vulnerability by connecting to the messaging service ports of the affected system. To exploit this vulnerability, the attacker must be able to send network traffic to interfaces within the VPN0 logical network. This network may be restricted to protect logical or physical adjacent networks, depending on device deployment configuration. A successful exploit could allow the attacker to view and inject messages into the messaging service, which can cause configuration changes or cause the system to reload.Show less
1Thoughtworks
1Gocd
Nov 21, 2024
Sep 7, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This...Show more
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the server GoCD Server or Agent are installed on to modify executables or components of the installation. This does not affect zip file-based installs, installations to other platforms, or installations inside `Program Files` or `Program Files (x86)`. This issue is fixed in GoCD 22.2.0 installers. As a workaround, if the server or agent is installed outside of `Program Files (x86)`, verify the the permission of the Server or Agent installation directory to ensure the `Everyone` user group does not have `Full Control`, `Modify` or `Write` permissions.Show less
1Opensuse
1Canna
Nov 21, 2024
Sep 7, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Back...Show more
A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.Show less
1Diagrams
1Drawio
Nov 21, 2024
Sep 2, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
1Tooljet
1Tooljet
Nov 21, 2024
Aug 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it wo...Show more
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).Show less
3Debian
LinuxRedhat
3Debian Linux
Enterprise LinuxLinux Kernel
Nov 21, 2024
Aug 26, 2022
N/A· v4
7.0 HIGH· v3
N/A· v2
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to ef...Show more
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.Show less
1Apple
2Mac Os X
Macos
May 29, 2025
Aug 24, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to access sensitive user information...Show more
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Nov 21, 2024
Aug 24, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group executio...Show more
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.Show less