A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the authorization verifications during the VPN authentication flow. An attacker could exploit this vulnerability by sending a crafted packet during a VPN authentication. The attacker must have valid credentials to establish a VPN connection. A successful exploit could allow the attacker to establish a VPN connection with access privileges from a different user.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adaptive_security_appliance_software | Cisco | 9.6.1 (including) | 9.6.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.1.3 (including) | 9.6.1.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.1.5 (including) | 9.6.1.5 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.1.10 (including) | 9.6.1.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2 (including) | 9.6.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.1 (including) | 9.6.2.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.2 (including) | 9.6.2.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.3 (including) | 9.6.2.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.7 (including) | 9.6.2.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.11 (including) | 9.6.2.11 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.13 (including) | 9.6.2.13 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.22 (including) | 9.6.2.22 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.2.23 (including) | 9.6.2.23 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3 (including) | 9.6.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.1 (including) | 9.6.3.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.3 (including) | 9.6.3.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.8 (including) | 9.6.3.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.9 (including) | 9.6.3.9 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.11 (including) | 9.6.3.11 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.12 (including) | 9.6.3.12 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.14 (including) | 9.6.3.14 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.17 (including) | 9.6.3.17 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.3.20 (including) | 9.6.3.20 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4 (including) | 9.6.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.3 (including) | 9.6.4.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.5 (including) | 9.6.4.5 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.6 (including) | 9.6.4.6 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.8 (including) | 9.6.4.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.10 (including) | 9.6.4.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.12 (including) | 9.6.4.12 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.14 (including) | 9.6.4.14 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.17 (including) | 9.6.4.17 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.18 (including) | 9.6.4.18 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.20 (including) | 9.6.4.20 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.22 (including) | 9.6.4.22 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.23 (including) | 9.6.4.23 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.24 (including) | 9.6.4.24 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.25 (including) | 9.6.4.25 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.29 (including) | 9.6.4.29 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.30 (including) | 9.6.4.30 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.34 (including) | 9.6.4.34 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.36 (including) | 9.6.4.36 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.40 (including) | 9.6.4.40 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.41 (including) | 9.6.4.41 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.42 (including) | 9.6.4.42 (including) |
Adaptive_security_appliance_software | Cisco | 9.6.4.45 (including) | 9.6.4.45 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1 (including) | 9.7.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.2 (including) | 9.7.1.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.4 (including) | 9.7.1.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.8 (including) | 9.7.1.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.15 (including) | 9.7.1.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.16 (including) | 9.7.1.16 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.21 (including) | 9.7.1.21 (including) |
Adaptive_security_appliance_software | Cisco | 9.7.1.24 (including) | 9.7.1.24 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.1 (including) | 9.8.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.1.5 (including) | 9.8.1.5 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.1.7 (including) | 9.8.1.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2 (including) | 9.8.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.8 (including) | 9.8.2.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.14 (including) | 9.8.2.14 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.15 (including) | 9.8.2.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.17 (including) | 9.8.2.17 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.20 (including) | 9.8.2.20 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.24 (including) | 9.8.2.24 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.26 (including) | 9.8.2.26 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.28 (including) | 9.8.2.28 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.33 (including) | 9.8.2.33 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.35 (including) | 9.8.2.35 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.2.38 (including) | 9.8.2.38 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3 (including) | 9.8.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.8 (including) | 9.8.3.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.11 (including) | 9.8.3.11 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.14 (including) | 9.8.3.14 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.16 (including) | 9.8.3.16 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.18 (including) | 9.8.3.18 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.21 (including) | 9.8.3.21 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.26 (including) | 9.8.3.26 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.3.29 (including) | 9.8.3.29 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4 (including) | 9.8.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.3 (including) | 9.8.4.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.7 (including) | 9.8.4.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.8 (including) | 9.8.4.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.10 (including) | 9.8.4.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.12 (including) | 9.8.4.12 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.15 (including) | 9.8.4.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.17 (including) | 9.8.4.17 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.20 (including) | 9.8.4.20 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.22 (including) | 9.8.4.22 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.25 (including) | 9.8.4.25 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.26 (including) | 9.8.4.26 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.29 (including) | 9.8.4.29 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.32 (including) | 9.8.4.32 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.33 (including) | 9.8.4.33 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.34 (including) | 9.8.4.34 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.35 (including) | 9.8.4.35 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.39 (including) | 9.8.4.39 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.40 (including) | 9.8.4.40 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.41 (including) | 9.8.4.41 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.43 (including) | 9.8.4.43 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.44 (including) | 9.8.4.44 (including) |
Adaptive_security_appliance_software | Cisco | 9.8.4.45 (including) | 9.8.4.45 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.1 (including) | 9.9.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.1.2 (including) | 9.9.1.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.1.3 (including) | 9.9.1.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.1.4 (including) | 9.9.1.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.1.5 (including) | 9.9.1.5 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2 (including) | 9.9.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.1 (including) | 9.9.2.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.9 (including) | 9.9.2.9 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.14 (including) | 9.9.2.14 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.18 (including) | 9.9.2.18 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.25 (including) | 9.9.2.25 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.27 (including) | 9.9.2.27 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.32 (including) | 9.9.2.32 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.36 (including) | 9.9.2.36 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.40 (including) | 9.9.2.40 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.47 (including) | 9.9.2.47 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.50 (including) | 9.9.2.50 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.52 (including) | 9.9.2.52 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.56 (including) | 9.9.2.56 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.59 (including) | 9.9.2.59 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.61 (including) | 9.9.2.61 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.66 (including) | 9.9.2.66 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.67 (including) | 9.9.2.67 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.74 (including) | 9.9.2.74 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.80 (including) | 9.9.2.80 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.83 (including) | 9.9.2.83 (including) |
Adaptive_security_appliance_software | Cisco | 9.9.2.85 (including) | 9.9.2.85 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1 (including) | 9.10.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.2 (including) | 9.10.1.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.7 (including) | 9.10.1.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.10 (including) | 9.10.1.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.11 (including) | 9.10.1.11 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.17 (including) | 9.10.1.17 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.22 (including) | 9.10.1.22 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.27 (including) | 9.10.1.27 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.30 (including) | 9.10.1.30 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.32 (including) | 9.10.1.32 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.37 (including) | 9.10.1.37 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.40 (including) | 9.10.1.40 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.42 (including) | 9.10.1.42 (including) |
Adaptive_security_appliance_software | Cisco | 9.10.1.44 (including) | 9.10.1.44 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.1 (including) | 9.12.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.1.2 (including) | 9.12.1.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.1.3 (including) | 9.12.1.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.2 (including) | 9.12.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.2.1 (including) | 9.12.2.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.2.4 (including) | 9.12.2.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.2.5 (including) | 9.12.2.5 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.2.9 (including) | 9.12.2.9 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.3 (including) | 9.12.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.3.2 (including) | 9.12.3.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.3.7 (including) | 9.12.3.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.3.9 (including) | 9.12.3.9 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.3.12 (including) | 9.12.3.12 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4 (including) | 9.12.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.2 (including) | 9.12.4.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.4 (including) | 9.12.4.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.7 (including) | 9.12.4.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.8 (including) | 9.12.4.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.10 (including) | 9.12.4.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.13 (including) | 9.12.4.13 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.18 (including) | 9.12.4.18 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.24 (including) | 9.12.4.24 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.26 (including) | 9.12.4.26 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.29 (including) | 9.12.4.29 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.30 (including) | 9.12.4.30 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.35 (including) | 9.12.4.35 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.37 (including) | 9.12.4.37 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.38 (including) | 9.12.4.38 (including) |
Adaptive_security_appliance_software | Cisco | 9.12.4.39 (including) | 9.12.4.39 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1 (including) | 9.13.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.2 (including) | 9.13.1.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.7 (including) | 9.13.1.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.10 (including) | 9.13.1.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.12 (including) | 9.13.1.12 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.13 (including) | 9.13.1.13 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.16 (including) | 9.13.1.16 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.19 (including) | 9.13.1.19 (including) |
Adaptive_security_appliance_software | Cisco | 9.13.1.21 (including) | 9.13.1.21 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.1 (including) | 9.14.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.1.6 (including) | 9.14.1.6 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.1.10 (including) | 9.14.1.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.1.15 (including) | 9.14.1.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.1.19 (including) | 9.14.1.19 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.1.30 (including) | 9.14.1.30 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.2 (including) | 9.14.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.2.4 (including) | 9.14.2.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.2.8 (including) | 9.14.2.8 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.2.13 (including) | 9.14.2.13 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.2.15 (including) | 9.14.2.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3 (including) | 9.14.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3.1 (including) | 9.14.3.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3.9 (including) | 9.14.3.9 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3.11 (including) | 9.14.3.11 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3.13 (including) | 9.14.3.13 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3.15 (including) | 9.14.3.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.3.18 (including) | 9.14.3.18 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.4 (including) | 9.14.4 (including) |
Adaptive_security_appliance_software | Cisco | 9.14.4.6 (including) | 9.14.4.6 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1 (including) | 9.15.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.1 (including) | 9.15.1.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.7 (including) | 9.15.1.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.10 (including) | 9.15.1.10 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.15 (including) | 9.15.1.15 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.16 (including) | 9.15.1.16 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.17 (including) | 9.15.1.17 (including) |
Adaptive_security_appliance_software | Cisco | 9.15.1.21 (including) | 9.15.1.21 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.1 (including) | 9.16.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.1.28 (including) | 9.16.1.28 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.2 (including) | 9.16.2 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.2.3 (including) | 9.16.2.3 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.2.7 (including) | 9.16.2.7 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.2.11 (including) | 9.16.2.11 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.2.13 (including) | 9.16.2.13 (including) |
Adaptive_security_appliance_software | Cisco | 9.16.2.14 (including) | 9.16.2.14 (including) |
Adaptive_security_appliance_software | Cisco | 9.17.1 (including) | 9.17.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.17.1.7 (including) | 9.17.1.7 (including) |
Assuming a user with a given identity, authorization is the process of determining whether that user can access a given resource, based on the user’s privileges and any permissions or other access-control specifications that apply to the resource. When access control checks are incorrectly applied, users are able to access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures, denial of service, and arbitrary code execution.