If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions,
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communi
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypas
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM o
A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, lo
Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attack
Windows Registry Elevation of Privilege Vulnerability
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Acce
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Acce
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a
Remote Desktop Client Remote Code Execution Vulnerability
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can mod
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an a
Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-
Windows Kernel Elevation of Privilege Vulnerability
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potential
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed c
A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This v
Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extensio
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affecte
Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with
Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user t
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prio
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring an
An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform
Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only use
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
An unauthorized user could possibly delete any file on the system.
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported vers
Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versio
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Suppo
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported ve
Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Pocket Outlook Sync(Pocke
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite).
Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are aff
Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticate
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started