Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access cont
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive informati
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some i
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by una
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix]
An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Relea
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to cal
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content provide
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of co
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attacker
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sen
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions st
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthor
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth
A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chro
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A perso
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access
An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system di
Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access se
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled.
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacke
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by cr
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may le
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Un
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, thi
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started