CWE-1220

Insufficient Granularity of Access Control

Parent: CWE-284 - Improper Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

79 vulnerabilities with CWE-1220
CVE-2024-39324 LOW
Aimeos Ai-admin-graphql < 2022.10.10 - Incorrect Authorization
CVSS 3.8
CVE-2024-39323 HIGH
Aimeos Ai-admin-graphql < 2022.10.10 - Incorrect Authorization
CVSS 7.1
CVE-2024-5389 HIGH
Lunary 1.2.13 - Info Disclosure
CVSS 8.1
CVE-2024-29200 MEDIUM
Kimai - Info Disclosure
CVSS 6.8
CVE-2024-26246 LOW
Microsoft Edge < - SSRF
CVSS 3.9
CVE-2024-2412 MEDIUM
Heimavista - RCE
CVSS 5.3
CVE-2023-31343 HIGH
SMM Handler < unknown - RCE
CVSS 7.5
CVE-2023-31342 HIGH
SMM Handler < - Memory Corruption
CVSS 7.5
CVE-2023-45217 HIGH
Intel Power Gadget < 3.6.0 - Improper Access Control
CVSS 8.8
CVE-2023-40070 HIGH
Intel Power Gadget - Improper Access Control
CVSS 8.8
CVE-2023-43040 MEDIUM
IBM Spectrum Fusion HCI 2.5.2-2.7.2 - Privilege Escalation
CVSS 6.5
CVE-2023-32259 MEDIUM
OpenText SMAX/AMX <2022.11 - Privilege Escalation
CVSS 6.5
CVE-2023-6725 MEDIUM
OpenStack Designate - Info Disclosure
CVSS 5.5
CVE-2023-50713 MEDIUM
Speckle Server <2.17.6 - Auth Bypass
CVSS 6.5
CVE-2023-44285 HIGH
Dell PowerProtect DD <7.13.0.10-6.2.1.110 - Privilege Escalation
CVSS 7.8
CVE-2023-4456 MEDIUM
openshift-logging LokiStack - Privilege Escalation
CVSS 5.7
CVE-2023-39418 LOW
PostgreSQL - Privilege Escalation
CVSS 3.1
CVE-2023-33127 HIGH
.NET - Privilege Escalation
CVSS 8.1
CVE-2023-3227 MEDIUM
fossbilling/fossbilling <0.5.0 - Info Disclosure
CVSS 5.7
CVE-2023-0205 MEDIUM
NVIDIA ConnectX-5/6/6-DX - DoS
CVSS 5.0
CVE-2023-0203 MEDIUM
NVIDIA ConnectX-5/6/6-DX - DoS
CVSS 5.0
CVE-2023-27591 HIGH
Miniflux < 2.0.43 - Information Disclosure
CVSS 7.5
CVE-2022-4813 MEDIUM
usememos/memos <0.9.1 - Info Disclosure
CVSS 4.3
CVE-2022-4801 MEDIUM
GitHub usememos/memos <0.9.1 - Info Disclosure
CVSS 5.3
CVE-2022-2475 CRITICAL
Haas Controller <100.20.000.1110 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 79