In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incor
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a fac
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via u
Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on t
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings.
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A speci
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payl
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker
Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.
Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SM
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in ma
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to a
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are ru
Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of t
EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulner
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect a
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view a
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K
Microsoft SharePoint Server Remote Code Execution Vulnerability
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through
Microsoft SharePoint Server Elevation of Privilege Vulnerability
An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/
feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low per
Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started