CWE-602

Medium likelihood

Client-Side Enforcement of Server-Side Security

Parent: CWE-693 - Protection Mechanism Failure

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

153 vulnerabilities with CWE-602
CVE-2023-23570 MEDIUM
Gallagher Command Centre <8.90.1620 - Privilege Escalation
CVSS 5.4
CVE-2023-42787 MEDIUM
Fortinet FortiManager <7.2.3, FortiAnalyzer <7.2.3 - RCE
CVSS 6.5
CVE-2023-3747 MEDIUM
Cloudflare WARP - Client-Side Enforcement Bypass via Local Date Manipulation
CVSS 5.5
CVE-2023-39218 MEDIUM
Zoom Rooms < 5.14.10 - Information Disclosure via Client-Side Enforcement Bypass
CVSS 6.1
CVE-2023-30955 MEDIUM
Foundry workspace-server <7.7.0 - Auth Bypass
CVSS 4.3
CVE-2023-20172 MEDIUM
Cisco Identity Services Engine - Authenticated Arbitrary File Delete and Read
CVSS 5.4
CVE-2023-20171 MEDIUM
Cisco Identity Services Engine - Authenticated Arbitrary File Delete and Read
CVSS 5.4
CVE-2023-20106 MEDIUM
Cisco Identity Services Engine - Authenticated Arbitrary File Read and Delete
CVSS 5.4
CVE-2023-0750 CRITICAL
lynx-technik yellobrik_pec_1864_firmware - Authentication Bypass via Client-Side Enforcement
CVSS 9.8
CVE-2023-0704 MEDIUM
Google Chrome <110.0.5481.77 - Auth Bypass
CVSS 6.5
CVE-2023-0581 MEDIUM
PrivateContent WordPress <8.4.3 - Auth Bypass
CVSS 5.3
CVE-2022-3310 MEDIUM
Google Chrome <106.0.5249.62 - Privilege Escalation
CVSS 6.5
CVE-2022-3308 HIGH
Google Chrome <106.0.5249.62 - Sandbox Escape
CVSS 7.4
CVE-2022-3047 MEDIUM
Google Chrome <105.0.5195.52 - Privilege Escalation
CVSS 6.5
CVE-2022-1525 CRITICAL
Cognex 3D-A1000 Dimensioning System <1.0.3 (3354) - Auth Bypass
CVSS 9.1
CVE-2022-31233 MEDIUM
Unisphere for PowerMax <9.2.3.15 - Privilege Escalation
CVSS 6.3
CVE-2022-20658 CRITICAL
Cisco Unified CCMP/CCDM - Privilege Escalation
CVSS 9.6
CVE-2021-36338 MEDIUM
Unisphere for PowerMax <9.2.2.2 - Privilege Escalation
CVSS 6.3
CVE-2021-21544 LOW
Dell EMC iDRAC9 < 4.40.00.00 - Authenticated Username Manipulation via Comment Section
CVSS 2.7
CVE-2021-21531 HIGH
Dell Unisphere for PowerMax <9.2.1.6 - Auth Bypass
CVSS 8.1
CVE-2020-27268 MEDIUM
SOOIL Developments Co., Ltd Diabecare RS - Auth Bypass
CVSS 6.5
CVE-2020-24683 CRITICAL
S+ Operations <2.1 SP1 - Auth Bypass
CVSS 9.8
CVE-2020-5345 MEDIUM
Dell EMC Unisphere for PowerMax < 9.1.0.17 - Authenticated Authorization Bypass
CVSS 6.4
CVE-2020-8162 HIGH
Rails <5.2.4.2, <6.0.3.1 - Info Disclosure
CVSS 7.5
CVE-2017-12161 HIGH
Keycloak < 3.4.2 - Password Reset Token Spoofing via Hosts File Manipulation
CVSS 8.8
Details
Vulnerabilities 153
Exploit Likelihood Medium