PillarIncomplete
CWE-284Improper Access Control
Category: other
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Common consequences· 1
- Other — Varies by Context
Potential mitigations· 2
- [Architecture and Design, Operation]Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- [Architecture and Design]
Related CAPEC attack patterns· 17
References
Exploits (incoming)12
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | WebView Exposurecapec-503 | 100% | live |
| AttackPattern | Install New Servicecapec-550 | 100% | live |
| AttackPattern | Replace File Extension Handlerscapec-556 | 100% | live |
| AttackPattern | Disable Security Softwarecapec-578 | 100% | live |
| AttackPattern | Add Malicious File to Shared Webrootcapec-563 | 100% | live |
| AttackPattern | Embedding Scripts within Scriptscapec-19 | 100% | live |
| AttackPattern | Intent Spoofcapec-502 | 100% | live |
| AttackPattern | Modification of Windows Service Configurationcapec-478 | 100% | live |
| AttackPattern | Incomplete Data Deletion in a Multi-Tenant Environmentcapec-546 | 100% | live |
| AttackPattern | Data Injected During Configurationcapec-536 | 100% | live |
| AttackPattern | Replace Trusted Executablecapec-558 | 100% | live |
| AttackPattern | Run Software at Logoncapec-564 | 100% | live |
Compliance frameworks addressing this (incoming)38
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | owasp_top10-a10 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm05 | 100% | live |
| ComplianceControl | pci_dss_v4-r12 | 100% | live |
| ComplianceControl | iso27701-a.7.2.1 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm08 | 100% | live |
| ComplianceControl | pci_dss_v4-r9 | 100% | live |
| ComplianceControl | nis2-art21d | 100% | live |
| ComplianceControl | nist_csf-id | 100% | live |
| ComplianceControl | owasp_llm_top10-llm01 | 100% | live |
| ComplianceControl | nist_csf-de | 100% | live |
| ComplianceControl | owasp_api_top10-api05 | 100% | live |
| ComplianceControl | nist_csf-gv | 100% | live |
| ComplianceControl | pci_dss_v4-r7 | 100% | live |
| ComplianceControl | owasp_top10-a01 | 100% | live |
| ComplianceControl | gdpr-art25 | 100% | live |
| ComplianceControl | cis_v8-6 | 100% | live |
| ComplianceControl | cis_v8-2 | 100% | live |
| ComplianceControl | owasp_api_top10-api08 | 100% | live |
| ComplianceControl | iso27701-a.7.3.6 | 100% | live |
| ComplianceControl | cis_v8-3 | 100% | live |
| ComplianceControl | gdpr-art35 | 100% | live |
| ComplianceControl | cis_v8-13 | 100% | live |
| ComplianceControl | cra-annexi-1 | 100% | live |
| ComplianceControl | cra-annexi-2 | 100% | live |
| ComplianceControl | pci_dss_v4-r4 | 100% | live |
| ComplianceControl | cis_v8-1 | 100% | live |
| ComplianceControl | dora-art13 | 100% | live |
| ComplianceControl | iso27001-a.5.23 | 100% | live |
| ComplianceControl | iso27001-a.8.21 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm10 | 100% | live |
Showing top 30 of 38 by confidence. Click any target to see the full neighbourhood.
(incoming)100
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-0206cve-2025-0206 | 0% | live |
| Vulnerability | CVE-2025-0213cve-2025-0213 | 0% | live |
| Vulnerability | CVE-2025-0335cve-2025-0335 | 0% | live |
| Vulnerability | CVE-2025-0341cve-2025-0341 | 0% | live |
| Vulnerability | CVE-2025-0402cve-2025-0402 | 0% | live |
| Vulnerability | CVE-2025-0463cve-2025-0463 | 0% | live |
| Vulnerability | CVE-2025-0650cve-2025-0650 | 0% | live |
| Vulnerability | CVE-2025-0702cve-2025-0702 | 0% | live |
| Vulnerability | CVE-2025-0802cve-2025-0802 | 0% | live |
| Vulnerability | CVE-2025-10083cve-2025-10083 | 0% | live |
| Vulnerability | CVE-2025-10085cve-2025-10085 | 0% | live |
| Vulnerability | CVE-2025-10201cve-2025-10201 | 0% | live |
| Vulnerability | CVE-2025-10398cve-2025-10398 | 0% | live |
| Vulnerability | CVE-2025-10424cve-2025-10424 | 0% | live |
| Vulnerability | CVE-2025-10425cve-2025-10425 | 0% | live |
| Vulnerability | CVE-2025-10427cve-2025-10427 | 0% | live |
| Vulnerability | CVE-2025-10428cve-2025-10428 | 0% | live |
| Vulnerability | CVE-2025-10447cve-2025-10447 | 0% | live |
| Vulnerability | CVE-2025-10480cve-2025-10480 | 0% | live |
| Vulnerability | CVE-2025-10600cve-2025-10600 | 0% | live |
| Vulnerability | CVE-2025-10608cve-2025-10608 | 0% | live |
| Vulnerability | CVE-2025-10615cve-2025-10615 | 0% | live |
| Vulnerability | CVE-2025-10616cve-2025-10616 | 0% | live |
| Vulnerability | CVE-2025-11078cve-2025-11078 | 0% | live |
| Vulnerability | CVE-2025-11318cve-2025-11318 | 0% | live |
| Vulnerability | CVE-2025-11347cve-2025-11347 | 0% | live |
| Vulnerability | CVE-2025-11351cve-2025-11351 | 0% | live |
| Vulnerability | CVE-2025-11352cve-2025-11352 | 0% | live |
| Vulnerability | CVE-2025-11353cve-2025-11353 | 0% | live |
| Vulnerability | CVE-2025-11354cve-2025-11354 | 0% | live |
Showing top 30 of 100 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.