277 vulnerabilities classified as CWE-264 (权限、特权和访问控制). AI Chinese analysis included.
This page documents security vulnerabilities associated with the Common Weakness Enumeration identifier CWE-264, specifically concerning permission and access control issues. It aggregates data from multiple software vendors and product lines to provide a comprehensive view of how this specific weakness manifests across different technology stacks. The collection includes detailed reports on various flaw types where incorrect handling of security permissions leads to unauthorized access, privilege escalation, or information disclosure. The time range covered spans several years, allowing analysts to observe trends and long-term remediation efforts by major technology providers. Readers can use this resource to track individual vendor advisories as they are issued, helping teams stay updated on specific patches or workarounds. Furthermore, the page serves as a reference for understanding the broader characteristics and impacts of the CWE-264 weakness class in software development and security auditing. Users can also look up a specific product’s vulnerability history to identify past incidents and assess the overall security posture of a system over time. This structured approach facilitates better risk management by highlighting recurring patterns in how permission checks are implemented or bypassed. By consolidating these disparate reports, the page aims to support security professionals in identifying root causes and implementing more robust access control mechanisms in their own environments. The information is presented in a neutral format, focusing on factual details regarding the nature of the flaws, affected versions, and resolution statuses without speculation or opinion.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2017-6620 | Cisco CVR100W Wireless-N VPN Router 安全漏洞 — Cisco CVR100W Wireless-N VPN Router | 5.8 | - | 2017-05-03 |
| CVE-2017-6624 | Cisco CallManager Express Cisco IOS Software 安全漏洞 — Cisco CallManager Express | 5.3 | - | 2017-05-03 |
| CVE-2017-3832 | Cisco Wireless LAN Controller 权限许可和访问控制问题漏洞 — Cisco Wireless LAN Controller | 7.5 | - | 2017-04-06 |
| CVE-2017-3819 | 多款Cisco产品StarOS 权限许可和访问控制问题漏洞 — Cisco StarOS | 8.8 | - | 2017-03-15 |
| CVE-2017-3831 | Cisco Mobility Express 1800 Series Access Points 权限许可和访问控制漏洞 — Cisco Mobility Express 1800 Access Point Series | 9.8 | - | 2017-03-15 |
| CVE-2017-3801 | Cisco UCS Director 权限许可和访问控制问题漏洞 — Cisco UCS Director versions 6.0.0.0 and 6.0.0.1 | 8.8 | - | 2017-02-15 |
| CVE-2017-3813 | Cisco AnyConnect Secure Mobility Client Software for Windows 授权问题漏洞 — Cisco AnyConnect Secure Mobility Client Software for Windows Versions prior to released versions 4.4.00243 and later and 4.3.05017 and later. | 7.1 | - | 2017-02-09 |
Vulnerabilities classified as CWE-264 (权限、特权和访问控制) represent 277 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.