Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content secur
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Repo
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are alwa
On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code ex
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra
Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdrag
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated,
Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinc
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthe
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthe
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an u
Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Se
A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual action
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorizati
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.3
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products runnin
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments.
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 an
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component re
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passe
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attack
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User a
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cook
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can d
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authen
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote a
A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authen
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated,
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, re
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Superviso
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modify
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertion
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against project
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on ne
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create
setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started