Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certai
Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the admi
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of
IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Fo
The VTEX [email protected] GraphQL API module does not properly restrict unauthorized access to private configuration dat
Azure Service Connector Security Feature Bypass Vulnerability
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to vali
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0,
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 11225
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 11225
Some access control products are vulnerable to a session hijacking attack because the product does not update the sessio
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability o
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry
Improper access control in the Intel(R) Unite(R) Hub software installer for Windows before version 4.2.34962 may allow a
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive info
netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the a
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp
NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI in
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with per
An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET r
Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcem
Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protecte
Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS
Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service co
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.000
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of
Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vuln
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central passwor
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-li
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access con
Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (compo
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default pa
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects so
A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this
Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local auth
A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affec
A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. It has been declared as critical. This vulnerability af
Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe b
Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to pote
Improper access control in some Intel(R) Unison(TM) software before version 10.12 may allow a privileged user to potenti
SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerab
Azure DevOps Server Elevation of Privilege Vulnerability
Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started