2060 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.
CWE-284 represents a critical security weakness where software fails to properly restrict access to sensitive resources, allowing unauthorized actors to interact with data or functions they should not reach. This flaw typically arises when developers neglect to implement robust authentication or authorization checks, enabling attackers to bypass security controls through direct URL manipulation, token forgery, or privilege escalation techniques. Exploitation often leads to severe consequences, including data breaches, unauthorized system modifications, or complete service disruption. To mitigate this risk, developers must enforce strict access control policies at every layer of the application architecture. This involves implementing comprehensive identity verification, applying the principle of least privilege, and rigorously validating user permissions before granting access to any protected resource, ensuring that only authenticated and authorized users can perform specific actions.
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return Truefunction runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2017-16766 | Synology DiskStation Manager 访问控制错误漏洞 — DiskStation Manager (DSM) | 6.4 | - | 2017-12-22 |
| CVE-2017-5254 | Cambium Networks ePMP 安全漏洞 — ePMP | 8.8 | - | 2017-12-20 |
| CVE-2017-15891 | Synology Calendar 访问控制错误漏洞 — Synology Calendar | 6.5 | - | 2017-12-08 |
| CVE-2017-12340 | 多款Cisco产品Cisco NX-OS System Software 安全漏洞 — Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches | 3.4 | - | 2017-11-30 |
| CVE-2017-14031 | Trihedral VTScada 访问控制错误漏洞 — Trihedral Engineering Limited VTScada | 7.1 | - | 2017-11-06 |
| CVE-2017-12262 | Cisco Application Policy Infrastructure Controller Enterprise Module 安全漏洞 — Cisco Application Policy Infrastructure Controller Enterprise Module | 8.8 | - | 2017-11-02 |
| CVE-2017-8447 | Elasticsearch X-Pack Security 安全漏洞 — Elastic X-Pack Security | 6.5 | - | 2017-09-28 |
| CVE-2017-8448 | Elastic X-Pack Alerting 安全漏洞 — Elastic X-Pack Alerting | 8.8 | - | 2017-09-28 |
| CVE-2017-6866 | Siemens XHQ 4和5 安全漏洞 — XHQ 4 (All versions before V4.7.1.3), XHQ 5 (All versions before V5.0.0.2) | 6.5 | - | 2017-08-07 |
| CVE-2017-7928 | Schweitzer Engineering Laboratories SEL-3620和SEL-3622 Security Gateway 安全漏洞 — Schweitzer Engineering Laboratories, Inc. SEL-3620 and SEL-3622 | 9.6 | - | 2017-08-07 |
| CVE-2017-7918 | Cambium Networks ePMP 访问控制错误漏洞 — Cambium Networks ePMP | 6.8 | - | 2017-06-21 |
| CVE-2017-8438 | Elastic X-Pack Security 权限许可和访问控制漏洞 — X-Pack Security | 8.8 | - | 2017-06-05 |
| CVE-2017-6016 | LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA 访问控制错误漏洞 — LCDS Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA | 7.8 | - | 2017-05-19 |
| CVE-2016-9368 | Eaton xComfort Ethernet Communication Interface 访问控制错误漏洞 — Eaton xComfort Ethernet Communication Interface | 7.5 | - | 2017-03-14 |
| CVE-2014-2365 | Advantech WebAccess Improper Access Control — WebAccess | 8.1 | - | 2014-07-19 |
| CVE-2012-6435 | Rockwell Automation ControlLogix PLC Improper Access Control — 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules | 9.8 | - | 2013-01-24 |
| CVE-2012-6439 | Rockwell Automation ControlLogix PLC Improper Access Control — 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules | 9.8 | - | 2013-01-24 |
| CVE-2012-6442 | Rockwell Automation ControlLogix PLC Improper Access Control — 1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules | 9.8 | - | 2013-01-24 |
| CVE-2012-6068 | 3S CoDeSys Improper Access Control — CODESYS Control Runtime embedded | 9.8 | Critical | 2013-01-21 |
| CVE-2009-2631 | Clientless SSL VPN products break web browser domain-based security models — Adaptive Security Appliance Web SSL VPN | 5.3 | - | 2009-12-04 |
Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2060 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.