VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 111 of 164
  • CVE-2023-46277HigOct 20, 2023
    risk 0.44cvss 7.8epss 0.00

    please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.)

  • CVE-2023-4822MedOct 16, 2023
    risk 0.44cvss 6.7epss 0.01

    Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer,…

  • CVE-2023-34043MedSep 27, 2023
    risk 0.44cvss 6.7epss 0.00

    VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

  • CVE-2023-32490MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

  • CVE-2022-45853MedMay 30, 2023
    risk 0.44cvss 6.7epss 0.00

    The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable…

  • CVE-2023-30601HigMay 30, 2023
    risk 0.44cvss 7.8epss 0.00

    Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability requires…

  • CVE-2023-20680MedApr 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664785; Issue ID: ALPS07664785.

  • CVE-2022-43863MedMar 22, 2023
    risk 0.44cvss 6.7epss 0.01

    IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425.

  • CVE-2022-37929MedDec 12, 2022
    risk 0.44cvss 6.7epss 0.00

    Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

  • CVE-2022-41948MedDec 8, 2022
    risk 0.44cvss 6.7epss 0.01

    DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerability. A DHIS2 user with authority to manage users can assign superuser privileges to themself by…

  • CVE-2022-32633MedDec 5, 2022
    risk 0.44cvss 6.7epss 0.00

    In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; Issue ID: ALPS07441637.

  • CVE-2022-41974HigOct 29, 2022
    risk 0.44cvss 7.8epss 0.01

    multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to…

  • CVE-2022-34438MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

  • CVE-2022-41032HigOct 11, 2022
    risk 0.44cvss 7.8epss 0.01

    NuGet Client Elevation of Privilege Vulnerability

  • CVE-2022-30121MedSep 23, 2022
    risk 0.44cvss 6.7epss 0.00

    The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

  • CVE-2022-33962MedAug 4, 2022
    risk 0.44cvss 6.7epss 0.00

    In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certain iRules commands may allow an attacker to bypass the access control restrictions for a self IP address, regardless of the port…

  • CVE-2022-26118MedJul 18, 2022
    risk 0.44cvss 6.7epss 0.00

    A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some…

  • CVE-2022-34754MedJul 13, 2022
    risk 0.44cvss 6.8epss 0.00

    A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (V2.12.0 and prior)

  • CVE-2022-26057MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a…

  • CVE-2022-31594MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.