Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 106/134
7.3
CVE-2022-41689

Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated us

7.3
CVE-2023-39259

Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability.

7.3
CVE-2023-5299

A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.

7.3
CVE-2023-39253

Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability.

7.3
CVE-2023-43086

Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local maliciou

7.3
CVE-2023-44289

Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious

7.3
CVE-2023-44290

Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious s

7.3
CVE-2023-39256

Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious

7.3
CVE-2023-39257

Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious

7.3
CVE-2023-6578

A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown

7.2
CVE-2022-42465

Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privilege

7.2
CVE-2023-22312

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation

7.2
CVE-2023-38167

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

7.2
CVE-2023-35179

A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-f

7.2
CVE-2022-37343

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially ena

7.2
CVE-2021-36036

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access

7.2
CVE-2023-40060

A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass m

7.1
CVE-2022-36441

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to

7.1
CVE-2023-21750

Windows Kernel Elevation of Privilege Vulnerability

7.1
CVE-2023-21752

Windows Backup Service Elevation of Privilege Vulnerability

7.1
CVE-2023-21980

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are aff

7.1
CVE-2023-31138

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3

7.1
CVE-2022-41690

Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticat

7.1
CVE-2022-40529

Memory corruption due to improper access control in kernel while processing a mapping request from root process.

7.1
CVE-2023-36635

An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a r

7.1
CVE-2023-40730

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app

7.1
CVE-2023-50928

"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneousl

7.0
CVE-2023-21531

Azure Service Fabric Container Elevation of Privilege Vulnerability

6.8
CVE-2022-46677

Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin c

6.8
CVE-2023-21922

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Su

6.8
CVE-2023-21493

Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to

6.8
CVE-2023-34470

AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network.

6.8
CVE-2023-1832

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant

6.8
CVE-2023-46033

D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The

6.8
CVE-2023-45844

The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an ar

6.8
CVE-2023-27879

Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to poten

6.7
CVE-2023-21969

Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1

6.7
CVE-2023-28070

Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A

6.7
CVE-2022-32578

Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user t

6.7
CVE-2022-40972

Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to

6.7
CVE-2023-29242

Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to po

6.7
CVE-2022-29871

Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated use

6.7
CVE-2023-27391

Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may a

6.7
CVE-2022-3746

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local

6.7
CVE-2023-37194

A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (

6.7
CVE-2022-38786

Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authentica

6.7
CVE-2023-44282

Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module.

6.7
CVE-2023-44292

Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module.

6.6
CVE-2023-27509

Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user

6.5
CVE-2022-45166

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of us

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started