VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 133 of 186
  • CVE-2023-32196MedOct 16, 2024
    risk 0.43cvss 6.6epss 0.01

    A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.

  • CVE-2024-44540MedSep 23, 2024
    risk 0.43cvss 6.6epss 0.00

    Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.

  • CVE-2024-39342MedSep 23, 2024
    risk 0.43cvss 6.6epss 0.00

    Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated…

  • CVE-2024-41903MedAug 13, 2024
    risk 0.43cvss 6.6epss 0.00

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to…

  • CVE-2024-29976MedJun 4, 2024
    risk 0.43cvss 6.5epss 0.09

    ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain…

  • CVE-2023-41784MedJan 4, 2024
    risk 0.43cvss 6.6epss 0.00

    Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

  • CVE-2023-7090MedDec 23, 2023
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

  • CVE-2023-34045MedOct 20, 2023
    risk 0.43cvss 6.6epss 0.00

    VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with…

  • CVE-2023-38734MedAug 22, 2023
    risk 0.43cvss 6.6epss 0.01

    IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.

  • CVE-2023-30024MedApr 28, 2023
    risk 0.43cvss 6.6epss 0.00

    The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a malicious version, leading to ransomware deployment on the…

  • CVE-2023-26600MedMar 6, 2023
    risk 0.43cvss 6.5epss 0.06

    ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

  • CVE-2021-42304MedNov 10, 2021
    risk 0.43cvss 6.6epss 0.01

    Azure RTOS Elevation of Privilege Vulnerability

  • CVE-2021-42303MedNov 10, 2021
    risk 0.43cvss 6.6epss 0.01

    Azure RTOS Elevation of Privilege Vulnerability

  • CVE-2021-42302MedNov 10, 2021
    risk 0.43cvss 6.6epss 0.01

    Azure RTOS Elevation of Privilege Vulnerability

  • CVE-2021-1371MedMar 24, 2021
    risk 0.43cvss 6.6epss 0.00

    A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration. This…

  • CVE-2021-1646MedJan 12, 2021
    risk 0.43cvss 6.6epss 0.01

    Windows WLAN Service Elevation of Privilege Vulnerability

  • CVE-2020-7274MedApr 15, 2020
    risk 0.43cvss 6.6epss 0.00

    Privilege escalation vulnerability in McTray.exe in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by…

  • CVE-2020-7259MedApr 15, 2020
    risk 0.43cvss 6.6epss 0.00

    Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file

  • CVE-2020-6584MedMar 16, 2020
    risk 0.43cvss 6.5epss 0.04

    Nagios Log Server 2.1.3 has Incorrect Access Control.

  • CVE-2019-16777HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.02

    Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any…