VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 128 of 164
  • CVE-2024-22068MedOct 10, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.

  • CVE-2024-20282MedApr 3, 2024
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could…

  • CVE-2024-25961MedMar 28, 2024
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2024-1442MedMar 7, 2024
    risk 0.39cvss 6.0epss 0.01

    A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

  • CVE-2023-51429MedDec 29, 2023
    risk 0.39cvss 6.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

  • CVE-2023-20193MedSep 7, 2023
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have…

  • CVE-2022-20907MedJul 22, 2022
    risk 0.39cvss 6.0epss 0.00

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could…

  • CVE-2022-20906MedJul 22, 2022
    risk 0.39cvss 6.0epss 0.00

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could…

  • CVE-2022-29164HigMay 6, 2022
    risk 0.39cvss 7.1epss 0.01

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions an attacker can create a workflow which produces a HTML artifact containing an HTML file that contains a script which uses XHR calls to interact…

  • CVE-2022-0144HigJan 11, 2022
    risk 0.39cvss 7.1epss 0.00

    shelljs is vulnerable to Improper Privilege Management

  • CVE-2020-3393MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. The attacker could execute IOS XE commands outside the application-hosting subsystem Docker container…

  • CVE-2017-5703MedApr 3, 2018
    risk 0.39cvss 6.0epss 0.00

    Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service.

  • CVE-2026-47725MedJul 28, 2026
    risk 0.38cvss epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. SameSite=Lax on the session cookie prevents most…

  • CVE-2026-46618MedJun 10, 2026
    risk 0.38cvss epss 0.00

    Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, before the round-1 security sweep, pkg/builder/builder.go passed Environment.spec.builder.command directly into…

  • CVE-2025-6723MedJan 30, 2026
    risk 0.38cvss epss 0.00

    Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions to assume the InSpec execution context,…

  • CVE-2025-12683MedNov 4, 2025
    risk 0.38cvss epss 0.00

    The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege…

  • CVE-2025-2324MedMar 19, 2025
    risk 0.38cvss 5.9epss 0.00

    Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before…

  • CVE-2024-44439MedOct 4, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote attacker to escalate privileges via the open port.

  • CVE-2024-27357MedJul 26, 2024
    risk 0.38cvss 5.8epss 0.00

    An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x for macOS. Local Privilege Escalation can occur during installations or updates by admins.

  • CVE-2024-5566MedJul 16, 2024
    risk 0.38cvss 5.8epss 0.00

    An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in…