CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-39259
HIGH
Dell OS Recovery Tool 2.2.4013, 2.3.7012.0, 2.3.7515.0 - Authenticated Privilege Escalation
CVSS 7.3
CVE-2023-31100
HIGH
Phoenix SecureCore Technology <=4.5.0.137 - Improper Access Control in SMI Handler
CVSS 8.4
CVE-2023-41570
MEDIUM
MikroTik RouterOS <7.12 - Info Disclosure
CVSS 5.3
CVE-2023-39228
MEDIUM
Intel Unison Software < 20.14.5683.0 - Unauthenticated Denial of Service via Network Access
CVSS 5.3
CVE-2023-39221
MEDIUM
Intel Unison - Privilege Escalation
CVSS 5.4
CVE-2023-38411
LOW
Intel Smart Campus <9.4 - Privilege Escalation
CVSS 3.9
CVE-2023-33872
MEDIUM
Intel Support <all - Info Disclosure
CVSS 5.5
CVE-2023-32279
HIGH
Intel Connectivity Performance Suite < 2.1123.214.2 - Unauthenticated Information Disclosure via Network Access
CVSS 7.5
CVE-2023-32204
HIGH
Intel One Boot Flash Update < 14.1.31 - Authenticated Privilege Escalation via Local Access
CVSS 8.8
CVE-2023-29157
HIGH
Intel(R) OFU <14.1.31 - Privilege Escalation
CVSS 8.4
CVE-2023-28397
HIGH
Intel Aptio V UEFI Firmware Integrator Tools - Authenticated Privilege Escalation via Local Access
CVSS 7.8
CVE-2023-27879
MEDIUM
Intel Optane Memory H20 Firmware < u4110553-g004 - Unauthenticated Info Disclosure via Physical Access
CVSS 6.8
CVE-2023-22448
MEDIUM
Intel Unison - Privilege Escalation
CVSS 5.9
CVE-2023-22285
HIGH
Intel Unison Software < 20.14.5683.0 - Unauthenticated Denial of Service via Network Access
CVSS 7.5
CVE-2023-44248
MEDIUM
FortiEDRCollectorWindows <= 5.2.0.4549, <= 5.0.3.1007, 4.0 - Local Denial of Service via Registry Key Tampering
CVSS 4.4
CVE-2023-36404
MEDIUM
Windows 10/11, Server 2016/2019/2022 Information Disclosure
CVSS 5.5
CVE-2023-26205
HIGH
FortiADC <7.1.2 - Privilege Escalation
CVSS 8.1
CVE-2023-46601
CRITICAL
Siemens COMOS - Improper Access Control in SQL Server Connection
CVSS 9.6
CVE-2023-43505
CRITICAL
Siemens COMOS - Improper Access Control in SMB Shares
CVSS 9.6
CVE-2023-43901
MEDIUM
EMSigner v2.8.7 - Privilege Escalation
CVSS 5.9
CVE-2023-6073
MEDIUM
Volkswagen ID.3 Firmware < 3.2 - Denial of Service and Volume Setting Spoofing via REST API
CVSS 5.7
CVE-2023-5543
LOW
moodle 4.0.0-4.0.10 - Improper Access Control via BigBlueButton Activity Duplication
CVSS 3.3
CVE-2023-5549
LOW
moodle < 3.9.24 and >= 4.3.0-rc2 - Improper Access Control in Category Management
CVSS 3.3
CVE-2023-5542
LOW
moodle < 4.3.0-rc2 - Improper Access Control in Group Membership Visibility
CVSS 3.3
CVE-2023-47110
CRITICAL
PrestaShop blockreassurance < 5.1.4 - Improper Access Control via AJAX Configuration Modification
CVSS 9.1
Details
Vulnerabilities
5,306