Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2017-04-03 CVE-2014-3930 Improper Access Control vulnerability in LG Project LG 1.01
lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.
network
low complexity
lg-project CWE-284
7.5
2017-04-03 CVE-2014-3929 Improper Access Control vulnerability in LG Project LG
The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.
network
low complexity
lg-project CWE-284
7.5
2017-04-03 CVE-2014-3928 Improper Access Control vulnerability in LG Project LG
Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.
network
low complexity
lg-project CWE-284
critical
9.8
2017-04-02 CVE-2016-8798 Improper Access Control vulnerability in Huawei Usg5500 Firmware V300R001C00/V300R001C10
Huawei USG5500 with software V300R001C00 and V300R001C00 allows attackers to bypass the anti-DDoS module of the USGs to cause a denial of service condition on the backend server.
network
low complexity
huawei CWE-284
7.5
2017-04-02 CVE-2016-8794 Improper Access Control vulnerability in Huawei Mate 8 Firmware, Mate S Firmware and P8 Firmware
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before CRR-TL00C01B368, Versions before CRR-UL00C00B368, Versions before CRR-UL20C00B368; and P8 phones with software Versions before GRA-TL00C01B366, Versions before GRA-CL00C92B366, Versions before GRA-CL10C92B366, Versions before GRA-UL00C00B366, Versions before GRA-UL10C00B366 allow attackers with graphic or Camera privilege to crash the system or escalate privilege.
network
high complexity
huawei CWE-284
7.1
2017-04-02 CVE-2016-8793 Improper Access Control vulnerability in Huawei Mate 8 Firmware, Mate S Firmware and P8 Firmware
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before CRR-TL00C01B368, Versions before CRR-UL00C00B368, Versions before CRR-UL20C00B368; and P8 phones with software Versions before GRA-TL00C01B366, Versions before GRA-CL00C92B366, Versions before GRA-CL10C92B366, Versions before GRA-UL00C00B366, Versions before GRA-UL10C00B366 allow attackers with graphic or Camera privilege to crash the system or escalate privilege.
local
high complexity
huawei CWE-284
6.7
2017-04-02 CVE-2016-8792 Improper Access Control vulnerability in Huawei Mate 8 Firmware, Mate S Firmware and P8 Firmware
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before CRR-TL00C01B368, Versions before CRR-UL00C00B368, Versions before CRR-UL20C00B368; and P8 phones with software Versions before GRA-TL00C01B366, Versions before GRA-CL00C92B366, Versions before GRA-CL10C92B366, Versions before GRA-UL00C00B366, Versions before GRA-UL10C00B366 allow attackers with graphic or Camera privilege to crash the system or escalate privilege.
network
high complexity
huawei CWE-284
7.1
2017-04-02 CVE-2016-8791 Improper Access Control vulnerability in Huawei Mate 8 Firmware, Mate S Firmware and P8 Firmware
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before CRR-TL00C01B368, Versions before CRR-UL00C00B368, Versions before CRR-UL20C00B368; and P8 phones with software Versions before GRA-TL00C01B366, Versions before GRA-CL00C92B366, Versions before GRA-CL10C92B366, Versions before GRA-UL00C00B366, Versions before GRA-UL10C00B366 allow attackers with graphic or Camera privilege to crash the system or escalate privilege.
network
high complexity
huawei CWE-284
7.1
2017-04-02 CVE-2016-8274 Improper Access Control vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE has a dynamic link library (DLL) hijack vulnerability; an attacker can make the system load malicious DLL files to execute arbitrary code.
local
low complexity
huawei CWE-284
7.8
2017-04-02 CVE-2016-8273 Improper Access Control vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC.
local
low complexity
huawei CWE-284
7.8