VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 131 of 164
  • CVE-2024-5909MedJun 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

  • CVE-2024-2431MedMar 13, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.

  • CVE-2022-32931MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information.

  • CVE-2023-5960MedNov 28, 2023
    risk 0.36cvss 5.5epss 0.00

    An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.

  • CVE-2023-5797MedNov 28, 2023
    risk 0.36cvss 5.5epss 0.00

    An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…

  • CVE-2023-5650MedNov 28, 2023
    risk 0.36cvss 5.5epss 0.00

    An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16…

  • CVE-2023-37925MedNov 28, 2023
    risk 0.36cvss 5.5epss 0.00

    An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…

  • CVE-2023-35140MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.

  • CVE-2023-21376MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-4936MedOct 11, 2023
    risk 0.36cvss 5.5epss 0.00

    It is possible to sideload a compromised DLL during the installation at elevated privilege.

  • CVE-2023-35671MedSep 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information…

  • CVE-2023-4140MedAug 4, 2023
    risk 0.36cvss 6.6epss 0.01

    The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such…

  • CVE-2023-29819MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.

  • CVE-2023-1548MedApr 18, 2023
    risk 0.36cvss 5.5epss 0.00

    A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)

  • CVE-2022-3421MedOct 17, 2022
    risk 0.36cvss 5.6epss 0.00

    An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in that directory with execute…

  • CVE-2017-20028MedJun 9, 2022
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. It…

  • CVE-2022-20112MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2022-20051MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue…

  • CVE-2021-43211MedNov 24, 2021
    risk 0.36cvss 5.5epss 0.01

    Windows 10 Update Assistant Elevation of Privilege Vulnerability

  • CVE-2021-42280MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    Windows Feedback Hub Elevation of Privilege Vulnerability