← Back
CWE-284

5,081 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,081)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Openstack
Redhat
2Octavia
Openstack
Nov 21, 2024
Jun 3, 2019
N/A· v4
8.0 HIGH· v3
6.8 MEDIUM· v2
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant...Show more
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.Show less
1Linuxfoundation
1Osquery
Nov 21, 2024
Jun 3, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those cir...Show more
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said malicious executable with SYSTEM permissions. The solution is to migrate installations to the 'Program Files' directory on Windows which restricts unprivileged write access. This issue affects osquery prior to v3.4.0.Show less
1Quest
1Kace Systems Management Appliance Firmware
Nov 21, 2024
Jun 3, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vuln...Show more
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. A malicious internal user could also gain administrator privileges of this appliance and use it to visit a malicious link that exploits this vulnerability. This could cause the application to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. An unauthenticated, remote attacker could add an administrator-level account or change the appliance's settings.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
7.1 HIGH· v3
6.8 MEDIUM· v2
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permiss...Show more
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
5.3 MEDIUM· v3
7.1 HIGH· v2
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensor...Show more
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulne...Show more
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.Show less
1Bosch
1Smart Home Controller Firmware
Nov 21, 2024
May 29, 2019
N/A· v4
8.0 HIGH· v3
6.8 MEDIUM· v2
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggeri...Show more
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggering and restoring backups. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.Show less
1Qualcomm
37Mdm9150 Firmware
Mdm9206 FirmwareMdm9607 Firmware+34 more
Nov 21, 2024
May 24, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdr...Show more
Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20Show less
1Sensiolabs
1Symfony
Nov 21, 2024
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password val...Show more
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
1Citrix
2Receiver
Workspace
Nov 6, 2025
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
1Cisco
2715454 M Wse K9 Firmware
Analog Voice Network Interface Modules FirmwareAsa 5500 Firmware+24 more
Nov 21, 2024
May 13, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image...Show more
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.Show less
1Whatsapp
2Whatsapp
Whatsapp Business
Nov 21, 2024
May 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent kno...Show more
A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38.Show less
1Ge
1Ge Communicator
Nov 21, 2024
May 9, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system.
1Ge
1Ge Communicator
Nov 21, 2024
May 9, 2019
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scrip...Show more
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.Show less
1Wincofireworks
1Fw 1007 Firmware
Nov 21, 2024
May 8, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.
1Cisco
2Adaptive Security Appliance Software
Firepower Threat Defense
Nov 21, 2024
May 3, 2019
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the...Show more
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected device. An attacker could exploit this vulnerability by sending crafted packets to the management interface of an affected device. A successful exploit could allow the attacker to bypass the Layer 2 (L2) filters and send data directly to the kernel of the affected device. A malicious frame successfully delivered would make the target device generate a specific syslog entry.Show less