6 vulnerabilities classified as CWE-254 (7PK-安全功能). AI Chinese analysis included.
This page covers security vulnerabilities associated with the CWE-254 weakness type, specifically focusing on the failure to protect objects against unauthorized access within various vendor products and software systems. The content aggregates vulnerability records spanning the last decade, capturing data from initial disclosures through to recent patch releases to ensure a comprehensive historical perspective. By utilizing this aggregation, researchers and security professionals can track specific vendor advisories related to this class of flaws, allowing for better situational awareness regarding organizational risk exposure. Users can also gain a deeper understanding of the CWE-254 weakness class itself, analyzing common patterns in how developers fail to implement proper access control mechanisms. Furthermore, the page serves as a lookup tool for examining the vulnerability history of individual products, helping teams identify if their software stack contains known affected versions or if they have been exposed to exploits targeting this specific failure mode. This resource is designed to support threat modeling and remediation prioritization by highlighting the prevalence and impact of these access control failures across different technology sectors. It does not include marketing language or promotional content, strictly providing factual data points and references to official advisories. The scope is limited to verified vulnerabilities that map directly to the CWE-254 definition, excluding related but distinct weakness types. This approach ensures that users receive precise, actionable information without unnecessary noise or irrelevant entries.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-43177 | Devise-Two-Factor 安全漏洞 — devise-two-factor | 5.3 | - | 2022-04-11 |
| CVE-2021-40006 | Huawei HarmonyOS Wearables 加密问题漏洞 — HarmonyOS | 7.5 | - | 2022-01-07 |
| CVE-2018-6336 | Facebook osquery 安全特征问题漏洞 — osquery | 7.8 | - | 2018-12-31 |
| CVE-2018-0353 | Cisco Web Security Appliance AsyncOS 安全特征问题漏洞 — Cisco Web Security Appliance unknown | 6.5 | - | 2018-06-07 |
| CVE-2018-0110 | Cisco WebEx Meetings Server 安全漏洞 — Cisco WebEx Meetings Server | 8.1 | - | 2018-01-18 |
| CVE-2017-12353 | Cisco Email Security Appliance Cisco AsyncOS Software Multipurpose Internet Mail Extensions scanner 安全漏洞 — Cisco Email Security Appliance | 5.8 | - | 2017-11-30 |
Vulnerabilities classified as CWE-254 (7PK-安全功能) represent 6 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.