CWE-284
5,081 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,081)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Openstack Redhat2Octavia OpenstackNov 21, 2024 Jun 3, 2019 N/A· v4 8.0 HIGH· v3 6.8 MEDIUM· v2 An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant...Show more |
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those cir...Show more |
1Quest 1Kace Systems Management Appliance Firmware Nov 21, 2024 Jun 3, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vuln...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permiss...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 5.3 MEDIUM· v3 7.1 HIGH· v2 A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensor...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 5.7 MEDIUM· v3 2.9 LOW· v2 A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulne...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 8.0 HIGH· v3 6.8 MEDIUM· v2 A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggeri...Show more |
1Qualcomm 37Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+34 moreNov 21, 2024 May 24, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdr...Show more |
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password val...Show more |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control. |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. |
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 May 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. |
Citrix Workspace App before 1904 for Windows has Incorrect Access Control. |
1Cisco 2715454 M Wse K9 Firmware Analog Voice Network Interface Modules FirmwareAsa 5500 Firmware+24 moreNov 21, 2024 May 13, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image...Show more |
1Whatsapp 2Whatsapp Whatsapp BusinessNov 21, 2024 May 10, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent kno...Show more |
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system. |
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scrip...Show more |
1Wincofireworks 1Fw 1007 Firmware Nov 21, 2024 May 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability. |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 May 3, 2019 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the...Show more |