← Back
CWE-284

7,480 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,480)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
1Aptio V Uefi Firmware Integrator Tools
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.
1Intel
4Optane Memory H20 With Solid State Storage Firmware
Optane Ssd 905p FirmwareOptane Ssd Dc P4800x Firmware+1 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
1Intel
1In Band Manageability
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Unison
Jun 17, 2026
Nov 14, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
1Intel
1Battery Life Diagnostic Tool
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Aptio V Uefi Firmware Integrator Tools
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Aptio V Uefi Firmware Integrator Tools
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.
1Fortinet
1Fortiedr
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next...Show more
An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.Show less
1Microsoft
11Windows 10 1607
Windows 10 1809Windows 10 21h2+8 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Fortinet
1Fortiadc
Jun 17, 2026
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate t...Show more
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.Show less
1Siemens
1Comos
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access...Show more
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.Show less
1Siemens
1Comos
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
2Emsigner
Emudhra
2Emsigner
Emsigner
Aug 28, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.
1Volkswagen
1Id.3 Firmware
Jun 17, 2026
Nov 10, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio...Show more
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls. Show less
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 9, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 9, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
1Prestashop
1Customer Reassurance Block
Jun 17, 2026
Nov 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the config...Show more
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in version 5.1.4.Show less