CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could a
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user
On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopba
A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Le
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using e
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard l
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 al
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an a
Cloudera Manager through 5.15 has Incorrect Access Control.
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 a
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication an
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (S
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Pla
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to ga
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malic
Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an
pyxtrlock 0.3 and earlier is affected by: Incorrect Access Control. The impact is: False locking impression when run in
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSave
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to u
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emul
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x b
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey informatio
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perfo
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to c
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-12
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indo
A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJ
An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a cl
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on cert
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started