VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 113 of 164
  • CVE-2020-15797MedOct 13, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to…

  • CVE-2020-3396MedSep 24, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections.…

  • CVE-2020-0403MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product:…

  • CVE-2020-5916MedAug 26, 2020
    risk 0.44cvss 6.8epss 0.01

    In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file reads outside of the web root directory.

  • CVE-2020-10290MedAug 21, 2020
    risk 0.44cvss 6.8epss 0.00

    Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate…

  • CVE-2020-7305MedAug 13, 2020
    risk 0.44cvss 6.7epss 0.01

    Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.

  • CVE-2020-13776MedJun 3, 2020
    risk 0.44cvss 6.7epss 0.00

    systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for…

  • CVE-2020-6992MedApr 15, 2020
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to the arbitrary execution of code. This vulnerability is only…

  • CVE-2020-7273MedApr 15, 2020
    risk 0.44cvss 6.7epss 0.00

    Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some…

  • CVE-2020-8873MedMar 23, 2020
    risk 0.44cvss 6.7epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific…

  • CVE-2013-2016HigDec 30, 2019
    risk 0.44cvss 7.8epss 0.01

    A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the…

  • CVE-2013-4867MedDec 27, 2019
    risk 0.44cvss 6.3epss 0.02

    Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

  • CVE-2011-2910MedNov 15, 2019
    risk 0.44cvss 6.7epss 0.00

    The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege…

  • CVE-2013-4251HigNov 4, 2019
    risk 0.44cvss 7.8epss 0.00

    The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

  • CVE-2019-9443MedSep 6, 2019
    risk 0.44cvss 6.7epss 0.00

    In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege due to a set_fs() call without restoring the previous limit with System execution privileges needed. User interaction…

  • CVE-2018-0671MedJan 9, 2019
    risk 0.44cvss 6.7epss 0.00

    Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows system via unspecified vectors.

  • CVE-2018-0428MedAug 15, 2018
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due to improper…

  • CVE-2018-6674MedMay 25, 2018
    risk 0.44cvss 6.8epss 0.00

    Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges…

  • CVE-2018-4844MedMar 20, 2018
    risk 0.44cvss 6.7epss 0.00

    A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write access from one HMI project cache folder to…

  • CVE-2017-6152MedMar 8, 2018
    risk 0.44cvss 6.7epss 0.00

    A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.