Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive
Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly fi
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prio
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic.
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to
Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2
Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the
Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allo
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 an
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment obje
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by
Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of servi
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from
Carel Boss Mini 1.5.0 has Improper Access Control.
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In cert
The public API error causes for the attacker to be able to bypass API access control.
The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource u
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attac
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive
A denial of service vulnerability exists in the ucloud_del_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14
A denial of service vulnerability exists in the confctl_set_wan_cfg functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.0
Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use t
An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One
The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerabil
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with networ
There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote a
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthen
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaC
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started