A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could a
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and olde
Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attack
A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Se
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. Ho
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati
An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware
An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AW
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code exe
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.1
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA So
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course manag
In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker
MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access th
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permiss
In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged,
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allow
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a s
Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\
Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earl
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect cont
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation servic
A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edi
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 tha
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files
An unprotected logging route may allow an attacker to write endless log statements into the database without space limit
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this v
In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logg
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing cou
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Securi
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group c
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Sof
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior
UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unre
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allo
A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cis
Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authentica
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an
On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewa
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started