Vulnerabilities (CVE)

Filtered by CWE-284
Total 7905 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-44282 1 Dell 1 Repository Manager 2026-06-17 N/A 6.7 MEDIUM
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.
CVE-2023-44248 1 Fortinet 1 Fortiedr 2026-06-17 N/A 4.4 MEDIUM
An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.
CVE-2023-44118 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 9.1 CRITICAL
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2023-44031 1 Reprisesoftware 1 Reprise License Manager 2026-06-17 N/A 7.5 HIGH
Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request.
CVE-2023-43849 1 Aten 2 Pe6208, Pe6208 Firmware 2026-06-17 N/A 6.5 MEDIUM
Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image via HTTP POST requests. This may result in DoS or remote code execution.
CVE-2023-43848 1 Aten 2 Pe6208, Pe6208 Firmware 2026-06-17 N/A 8.0 HIGH
Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall settings of the device as if they were the administrator via HTTP POST request.
CVE-2023-43847 1 Aten 2 Pe6208, Pe6208 Firmware 2026-06-17 N/A 5.3 MEDIUM
Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to control all the outlets as if they were the administrator via HTTP POST requests.
CVE-2023-43814 1 Discourse 1 Discourse 2026-06-17 N/A 3.7 LOW
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for groups of poll participants. This impacts private polls where the results were intended to only be viewable by authorized users. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. There is no workaround for this issue apart from upgrading to the fixed version.
CVE-2023-43748 1 Intel 1 Graphics Performance Analyzers Framework 2026-06-17 N/A 7.8 HIGH
Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2023-43696 1 Sick 2 Apu0200, Apu0200 Firmware 2026-06-17 N/A 8.2 HIGH
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
CVE-2023-43626 2026-06-17 N/A 7.5 HIGH
Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2023-43517 1 Qualcomm 38 Qam8255p, Qam8255p Firmware, Qam8295p and 35 more 2026-06-17 N/A 8.4 HIGH
Memory corruption in Automotive Multimedia due to improper access control in HAB.
CVE-2023-43505 1 Siemens 1 Comos 2026-06-17 N/A 9.6 CRITICAL
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.
CVE-2023-43491 1 Peplink 2 Smart Reader, Smart Reader Firmware 2026-06-17 N/A 5.3 MEDIUM
An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
CVE-2023-43489 1 Intel 1 Computing Improvement Program 2026-06-17 N/A 5.5 MEDIUM
Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2023-43487 2026-06-17 N/A 4.7 MEDIUM
Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2023-43318 1 Tp-link 2 Tl-sg2210p, Tl-sg2210p Firmware 2026-06-17 N/A 8.8 HIGH
TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
CVE-2023-43119 1 Extremenetworks 1 Exos 2026-06-17 N/A 9.8 CRITICAL
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
CVE-2023-43089 1 Dell 1 Rugged Control Center 2026-06-17 N/A 4.4 MEDIUM
Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.
CVE-2023-43086 1 Dell 1 Command\|configure 2026-06-17 N/A 7.3 HIGH
Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modify files inside installation folder during application upgrade, leading to privilege escalation.