← Back
CWE-285

1,315 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Digium
2Asterisk
Certified Asterisk
May 6, 2026
Dec 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has...Show more
An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has a liberal definition for whitespace when attempting to strip the content between a SIP header name and a colon character. Rather than following RFC 3261 and stripping only spaces and horizontal tabs, Asterisk treats any non-printable ASCII character as if it were whitespace. This means that headers such as Contact\x01: will be seen as a valid Contact header. This mostly does not pose a problem until Asterisk is placed in tandem with an authenticating SIP proxy. In such a case, a crafty combination of valid and invalid To headers can cause a proxy to allow an INVITE request into Asterisk without authentication since it believes the request is an in-dialog request. However, because of the bug described above, the request will look like an out-of-dialog request to Asterisk. Asterisk will then process the request as a new call. The result is that Asterisk can process calls from unvetted sources without any authentication. If you do not use a proxy for authentication, then this issue does not affect you. If your proxy is dialog-aware (meaning that the proxy keeps track of what dialogs are currently valid), then this issue does not affect you. If you use chan_pjsip instead of chan_sip, then this issue does not affect you.Show less
1Ge
2Bently Nevada 3500/22m Serial Firmware
Bently Nevada 3500/22m Usb Firmware
May 6, 2026
Nov 25, 2016
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier for remote attackers to obtain privileged access via unspecified vectors.
1Linux
1Linux Kernel
May 6, 2026
Oct 16, 2016
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with rest...Show more
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions.Show less
1Wptf Image Gallery Project
1Wptf Image Gallery
May 6, 2026
Oct 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote file download vulnerability in wptf-image-gallery v1.03
2Charybdis Project
Debian
2Charybdis
Debian Linux
May 6, 2026
Sep 21, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
1Emc
1Vipr Srm
May 6, 2026
Sep 18, 2016
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.
1Microsoft
3Windows 10
Windows 8.1Windows Rt 8.1
May 6, 2026
Sep 14, 2016
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attac...Show more
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attack on NTLM password hashes, aka "Microsoft Information Disclosure Vulnerability."Show less
1Huawei
6Rh1288 V3 Server Firmware
Rh2288 V3 Server FirmwareRh2288h V3 Server Firmware+3 more
May 6, 2026
Sep 7, 2016
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 s...Show more
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515 allow remote attackers to obtain passwords via a brute-force attack, related to "lack of authentication protection mechanisms."Show less
2Netgear
Nuuo
3Nvrmini 2
NvrsoloReadynas Surveillance
May 6, 2026
Aug 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefc...Show more
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.Show less
1Moxa
2Oncell G3001 Firmware
Oncell G3100v2 Firmware
May 6, 2026
Aug 24, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force...Show more
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.Show less
3Debian
HaxxOpensuse
3Debian Linux
LeapLibcurl
May 6, 2026
Aug 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously c...Show more
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.Show less
1Rockwellautomation
1Factorytalk Energrymetrix
May 6, 2026
Jul 28, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
1Google
1Chrome
May 6, 2026
Jul 23, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to b...Show more
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Google
1Chrome
May 6, 2026
Jul 23, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attack...Show more
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Emerson
1Deltav
May 6, 2026
May 22, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that...Show more
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.Show less