CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-43072
MEDIUM
Dell SmartFabric Storage Software <1.4 - Privilege Escalation
CVSS 4.4
CVE-2023-1832
MEDIUM
Candlepin < 4.3.7-3 - Improper Access Control
CVSS 6.8
CVE-2023-22618
HIGH
Nokia WaveLite Metro 200 - Unauthenticated Privilege Escalation via User Creation
CVSS 8.1
CVE-2023-0506
HIGH
ByDemes Airspace CCTV Web Service 2.616.BY00.11 - Privilege Escalation in Camera Control Panel
CVSS 8.8
CVE-2023-5353
MEDIUM
SuiteCRM < 7.14.1 - Improper Access Control
CVSS 6.5
CVE-2023-24844
HIGH
Qualcomm FastConnect and AR8035/QCA8081/QCA8337 Firmware - Memory Corruption in Access Control Core Library
CVSS 8.4
CVE-2023-21673
HIGH
Qualcomm FastConnect and AQT1000/AR8035 Firmware - Memory Corruption in VM Resource Manager
CVSS 8.7
CVE-2023-32572
MEDIUM
FlashArray Purity 6.3.0-6.3.6 - Improper Access Control in pgroup Retention Lock
CVSS 6.5
CVE-2023-28372
MEDIUM
FlashBlade Purity < 4.1.0 - Authenticated Availability Impact via Object Retention Extension
CVSS 6.5
CVE-2023-5288
CRITICAL
SICK SIM1012-0P0G200 Firmware - Unauthenticated Configuration Modification and Firmware Upload
CVSS 9.8
CVE-2023-32477
HIGH
Dell Common Event Enabler < 8.9.8.2 - Privilege Escalation via Improper Access Control
CVSS 7.8
CVE-2023-20223
HIGH
Cisco DNA Center < 2.3.5.4 - Unauthenticated Improper Access Control via API Request
CVSS 8.6
CVE-2023-32458
HIGH
Dell AppSync 4.4.0.0-4.6.0.0 - Privilege Escalation via Embedded Service Enabler
CVSS 7.3
CVE-2023-41322
MEDIUM
GLPI <10.0.10 - Privilege Escalation
CVSS 4.9
CVE-2023-41311
MEDIUM
Huawei EMUI and HarmonyOS - Improper Access Control in Audio Module
CVSS 5.3
CVE-2023-39376
MEDIUM
SiberianCMS 4.0.0-4.20.44 - Authenticated Security Feature Bypass
CVSS 6.5
CVE-2023-43141
CRITICAL
TOTOLINK A3700R and N600R Firmware - Improper Access Control
CVSS 9.8
CVE-2023-25525
HIGH
NVIDIA Cumulus Linux < 5.6.0 - Information Disclosure via VxLAN-Encapsulated IPv6 Packet Forwarding
CVSS 7.5
CVE-2023-38206
MEDIUM
Adobe ColdFusion <2023u2 - Privilege Escalation
CVSS 5.3
CVE-2023-38205
HIGH
KEV
Adobe ColdFusion <2018u18,2021u8,2023u2 - Privilege Escalation
CVSS 7.5
CVE-2023-40850
HIGH
netentsec NS-ASG 6.3 - Info Disclosure
CVSS 7.5
CVE-2023-20191
MEDIUM
Cisco IOS XR < 7.7.21 - Unauthenticated Access Control Bypass via MPLS Ingress ACL Processing
CVSS 5.8
CVE-2023-36638
MEDIUM
FortiAnalyzer 6.0.0-6.4.11 & FortiManager 6.4.0-6.4.11 - Privilege Escalation via Stolen GUI Session ID
CVSS 4.3
CVE-2023-34470
MEDIUM
AMI AptioV - Improper Access Control via Local Network
CVSS 6.8
CVE-2023-34469
MEDIUM
AMI AptioV - Improper Access Control via Physical Network
CVSS 4.9
Details
Vulnerabilities
5,306