VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 101 of 164
  • CVE-2022-38757HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in…

  • CVE-2022-31707HigDec 16, 2022
    risk 0.47cvss 7.2epss 0.01

    vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

  • CVE-2022-42459HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

  • CVE-2022-41835HigOct 19, 2022
    risk 0.47cvss 7.3epss 0.00

    In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

  • CVE-2022-31672HigAug 10, 2022
    risk 0.47cvss 7.2epss 0.01

    VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.

  • CVE-2022-36833HigAug 5, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.

  • CVE-2021-36784HigMay 2, 2022
    risk 0.47cvss 7.2epss 0.01

    A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

  • CVE-2022-20739HigApr 15, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to…

  • CVE-2022-0556HigApr 11, 2022
    risk 0.47cvss 7.3epss 0.00

    A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.

  • CVE-2022-26251HigApr 6, 2022
    risk 0.47cvss 7.2epss 0.02

    The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

  • CVE-2022-25311HigMar 8, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended…

  • CVE-2021-35534HigNov 18, 2021
    risk 0.47cvss 7.2epss 0.02

    Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to…

  • CVE-2021-33335HigAug 3, 2021
    risk 0.47cvss 7.2epss 0.01

    Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the…

  • CVE-2021-29792HigJul 12, 2021
    risk 0.47cvss 7.2epss 0.00

    IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user. IBM X-Force ID: 203450.

  • CVE-2020-24046HigSep 17, 2020
    risk 0.47cvss 7.2epss 0.03

    A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This restricted shell can be bypassed after changing the properties of the user admin…

  • CVE-2020-4603HigAug 27, 2020
    risk 0.47cvss 7.2epss 0.01

    IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 184880.

  • CVE-2019-11847HigAug 21, 2020
    risk 0.47cvss 7.3epss 0.00

    An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.

  • CVE-2020-7509HigJun 16, 2020
    risk 0.47cvss 7.2epss 0.01

    A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to elevate their privileges and delete files.

  • CVE-2020-12713HigJun 11, 2020
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges…

  • CVE-2020-13695HigJun 1, 2020
    risk 0.47cvss 7.2epss 0.02

    In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.