A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privi
A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an a
Windows Address Book Remote Code Execution Vulnerability
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default inst
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a loc
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC
NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with s
peertube is vulnerable to Improper Access Control
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which ma
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or auth
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which m
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E
An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated att
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerabilit
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf clus
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
A denial of service vulnerability exists in the confctl_set_master_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_0
A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WI
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall An
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a rem
py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to r
Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated,
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <=
HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an
OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending t
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim
Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and bel
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images ar
Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.
Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow
Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adapti
An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to t
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the f
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unaut
VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an un
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started