CWE-602
148 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
CVEs (148)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command Centre 8.90 prior to vEL...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low priv...Show more |
Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP,...Show more |
1Zoom 3Rooms Virtual Desktop InfrastructureZoomJun 17, 2026 Aug 8, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
1Palantir 1Foundry Workspace Server Jun 17, 2026 Jun 29, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability...Show more |
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker m...Show more |
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker m...Show more |
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker m...Show more |
1Lynx Technik 1Yellobrik Pec 1864 Firmware Jun 17, 2026 Apr 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to...Show more |
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low) |
The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been...Show more |
Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted applicatio...Show more |
Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) |
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page. |
1Cognex 13d A1000 Dimensioning System Firmware Jun 17, 2026 Sep 6, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side Enforcement of Server-Side Security, which could allow attackers to bypass web access controls by i...Show more |
1Dell 8Evasa Provider Virtual Appliance Powermax OsSolutions Enabler+5 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities...Show more |
1Dell 7Powermax Os Solutions EnablerSolutions Enabler Virtual Appliance+4 moreJun 17, 2026 Jan 21, 2022 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalit...Show more |
1Cisco 2Unified Contact Center Express Unified Contact Center Management PortalJun 17, 2026 Jan 14, 2022 N/A· v4 9.6 CRITICAL· v3 8.5 HIGH· v2 A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote a...Show more |
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the use...Show more |
1Dell 5Powermax Os Solutions EnablerSolutions Enabler Virtual Appliance+2 moreJun 17, 2026 Apr 30, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions. |