CWE-1220

Insufficient Granularity of Access Control

Parent: CWE-284 - Improper Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

85 vulnerabilities with CWE-1220
CVE-2025-3648 HIGH
ServiceNow Now Platform - Unauthenticated Data Inference via Range Query Requests
CVE-2025-27026 MEDIUM
Infinera G42 R6.1.3 - Privilege Escalation
CVSS 4.9
CVE-2025-4404 CRITICAL
Red Hat Enterprise Linux - Privilege Escalation via FreeIPA krbCanonicalName Uniqueness Bypass
CVSS 9.1
CVE-2025-5982 LOW
GitLab EE <17.10.8-18.0.2 - Auth Bypass
CVSS 3.7
CVE-2025-4979 MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Info Disclosure
CVSS 4.9
CVE-2025-1110 LOW
GitLab 18.0 - Insufficient Granularity of Access Control via GraphQL Query
CVSS 2.7
CVE-2025-32703 MEDIUM
Visual Studio 2017, 2019, 2022 - Information Disclosure via Insufficient Access Control
CVSS 5.5
CVE-2025-1278 MEDIUM
GitLab CE/EE <17.9.8-17.11.2 - Auth Bypass
CVSS 5.3
CVE-2025-31201 CRITICAL KEV
macOS < 15.4.1 - Pointer Authentication Bypass via Insufficient Access Control
CVSS 9.8
CVE-2025-2408 MEDIUM
GitLab CE/EE <17.8.7-17.10.4 - Auth Bypass
CVSS 5.3
CVE-2025-29987 HIGH
Dell PowerProtect Data Domain <8.3.0.15 - Privilege Escalation
CVSS 8.8
CVE-2025-20111 HIGH
Cisco NX-OS Software - Unauthenticated Denial of Service via Crafted Ethernet Frames
CVSS 7.4
CVE-2024-21962 HIGH
AMD EPYC 4005 Series Processors - Privilege Escalation and Arbitrary Code Execution via AMD RAID Driver
CVE-2024-4147 MEDIUM
lunary-ai/lunary <1.2.13 - Privilege Escalation
CVSS 6.5
CVE-2024-21947 HIGH
System Management Mode - Memory Corruption
CVSS 7.5
CVE-2024-33058 HIGH
Memory Corruption - Buffer Overflow
CVSS 7.5
CVE-2024-12619 MEDIUM
GitLab CE/EE <17.8.6-17.10.1 - Privilege Escalation
CVSS 5.2
CVE-2024-6696 MEDIUM
Hitachi Vantara Pentaho <10.2.0.0-9.3.0.9 - Info Disclosure
CVSS 4.9
CVE-2024-39279 MEDIUM
Intel(R) processors - Authenticated Denial of Service via UEFI Firmware Access Control
CVSS 6.5
CVE-2024-21971 MEDIUM
AMD Ryzen 5000 and 7000 Series Desktop Processors - Denial of Service via AMD Crash Defender Input Validation
CVSS 5.5
CVE-2024-53295 HIGH
Dell PowerProtect DD <8.3.0.0-7.13.1.20 - Privilege Escalation
CVSS 7.8
CVE-2024-11931 MEDIUM
GitLab CE/EE <17.6.4-17.7.3-17.8.1 - Info Disclosure
CVSS 6.4
CVE-2024-13272 MEDIUM
Drupal Paragraphs <2.0.2 - Info Disclosure
CVSS 6.3
CVE-2024-13256 HIGH
Drupal Email Contact <2.0.4 - Info Disclosure
CVSS 7.5
CVE-2024-52814 LOW
Argo Helm <0.45.0 - Privilege Escalation
CVSS 2.8
Details
Vulnerabilities 85