When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed req
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or
The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obta
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override as
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. T
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to t
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a mali
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that w
This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use thi
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access c
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether
This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, m
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated a
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an atta
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability.
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability.
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrato
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAll
By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to b
Vulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework
Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerabi
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack
A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module i
A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (Al
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where imprope
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection instal
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file
A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started