← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hitachienergy
2Counterparty Settlements And Billing
Retail Operations
Nov 21, 2024
Nov 17, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Jav...Show more
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.Show less
1Qr Redirector Project
1Qr Redirector
Nov 21, 2024
Nov 17, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscribe...Show more
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR RedirectsShow less
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Nov 21, 2024
Nov 16, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.
1Paloaltonetworks
1Pan Os
Nov 21, 2024
Nov 10, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hos...Show more
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this vulnerability enables an attacker to perform any operations allowed by the EC2 role in AWS. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20 VM-Series firewalls; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11 VM-Series firewalls; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14 VM-Series firewalls; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8 VM-Series firewalls. Prisma Access customers are not impacted by this issue.Show less
1Vivo
1Jovi Smart Scene
Nov 21, 2024
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
1Phoenix Media Rename Project
1Phoenix Media Rename
Nov 21, 2024
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones...Show more
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.Show less
1Wp Survey Plus Project
1Wp Survey Plus
Nov 21, 2024
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sa...Show more
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issuesShow less
1Tipsandtricks Hq
1Simple Download Monitor
Nov 21, 2024
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
1Legalweb
1Wp Dsgvo Tools
Nov 21, 2024
Nov 5, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting...Show more
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for an attacker to permanently delete an arbitrary post or page on the site by sending an AJAX request with the “action” parameter set to “admin-dismiss-unsubscribe” and the “id” parameter set to the post to be deleted. Sending such a request would move the post to the trash, and repeating the request would permanently delete the post in question.Show less
1Google
1Android
Nov 21, 2024
Nov 5, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
1Cisco
5Catalyst Pon Switch Cgp Ont 1p Firmware
Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 more
Nov 21, 2024
Nov 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
5Catalyst Pon Switch Cgp Ont 1p Firmware
Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 more
Nov 21, 2024
Nov 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
5Catalyst Pon Switch Cgp Ont 1p Firmware
Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 more
Nov 21, 2024
Nov 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Hashthemes
1Hashthemes Demo Importer
Nov 21, 2024
Nov 1, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that tr...Show more
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.Show less
1Imagesourcecontrol
1Image Source Control
Nov 21, 2024
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)
1Jupyterhub
1First Use Authenticator
Nov 21, 2024
Oct 28, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0...Show more
FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is known or guessed. One may upgrade to version 1.0.0 or apply a patch manually to mitigate the vulnerability. For those who cannot upgrade, there is no complete workaround, but a partial mitigation exists. One can disable user creation with `c.FirstUseAuthenticator.create_users = False`, which will only allow login with fully normalized usernames for already existing users prior to jupyterhub-firstuserauthenticator 1.0.0. If any users have never logged in with their normalized username (i.e. lowercase), they will still be vulnerable until a patch or upgrade occurs.Show less
1Cisco
10Adaptive Security Appliance Software
Asa 5505 FirmwareAsa 5512 X Firmware+7 more
Nov 21, 2024
Oct 27, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow...Show more
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could exploit this vulnerability by sending an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list. A successful exploit could allow the attacker to send an SNMP query to an affected device and retrieve information from the device. The attacker would need valid credentials to perform the SNMP query.Show less
1Cisco
2Firepower Threat Defense
Secure Firewall Management Center
Nov 26, 2024
Oct 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured ru...Show more
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit these vulnerabilities by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should be activated for the ENIP packet.Show less
1Parallels
1Parallels Desktop
Nov 21, 2024
Oct 25, 2021
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the WinAppHelper component. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13543.Show less
5Debian
FedoraprojectNetapp+2 more
5Clustered Data Ontap
Communications Diameter Signaling RouterDebian Linux+2 more
Nov 21, 2024
Oct 25, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged u...Show more
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.Show less