A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Ho
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could esc
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood gluc
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G
A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated
A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has it
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allo
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat D
An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope tha
A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning fea
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Ce
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, a
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and depend
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the in
A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free ti
Intuit Lacerte 2017 has Incorrect Access Control.
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivile
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict p
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CP
A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could
A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to r
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcod
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sim
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sen
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (S
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started