Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated us
Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability.
A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.
Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability.
Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local maliciou
Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious
Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious s
Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown
Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privilege
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-f
Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially ena
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass m
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to
Windows Kernel Elevation of Privilege Vulnerability
Windows Backup Service Elevation of Privilege Vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are aff
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.3
Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticat
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a r
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneousl
Azure Service Fabric Container Elevation of Privilege Vulnerability
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Su
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network.
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant
D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The
The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an ar
Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to poten
Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1
Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A
Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user t
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to
Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to po
Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated use
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may a
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (
Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authentica
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module.
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module.
Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of us
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started