VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 139 of 164
  • CVE-2025-1425MedMar 4, 2025
    risk 0.31cvss epss 0.00

    A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.

  • CVE-2024-13058MedDec 30, 2024
    risk 0.31cvss epss 0.00

    An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined storage subsystem. This issue only impacts SoftIron HyperCloud and related…

  • CVE-2024-9471MedOct 9, 2024
    risk 0.31cvss 4.7epss 0.00

    A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example,…

  • CVE-2024-26247MedMar 22, 2024
    risk 0.31cvss 4.7epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-28049MedFeb 6, 2024
    risk 0.31cvss 4.7epss 0.00

    Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.

  • CVE-2023-25647MedAug 17, 2023
    risk 0.31cvss 4.7epss 0.00

    There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

  • CVE-2023-0192MedApr 1, 2023
    risk 0.31cvss 4.7epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.

  • CVE-2022-32535MedJun 23, 2022
    risk 0.31cvss 4.8epss 0.01

    The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.

  • CVE-2021-42319MedNov 10, 2021
    risk 0.31cvss 4.7epss 0.00

    Visual Studio Elevation of Privilege Vulnerability

  • CVE-2021-41339MedOct 13, 2021
    risk 0.31cvss 4.7epss 0.00

    Microsoft DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2021-31839MedJun 10, 2021
    risk 0.31cvss 4.8epss 0.00

    Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify event information in the MA event folder. This allows a local user to either add false events or remove events from the event logs prior to them being sent to the…

  • CVE-2021-20334MedApr 6, 2021
    risk 0.31cvss 4.8epss 0.00

    A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and…

  • CVE-2019-6195MedFeb 14, 2020
    risk 0.31cvss 4.8epss 0.01

    An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication…

  • CVE-2019-3805MedMay 3, 2019
    risk 0.31cvss 4.7epss 0.00

    A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d…

  • CVE-2018-16888MedJan 14, 2019
    risk 0.31cvss 4.7epss 0.00

    It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned…

  • CVE-2018-19608MedDec 5, 2018
    risk 0.31cvss 4.7epss 0.00

    Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

  • CVE-2018-13400MedOct 23, 2018
    risk 0.31cvss 4.7epss 0.01

    Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version…

  • CVE-2018-10906MedJul 24, 2018
    risk 0.31cvss 5.3epss 0.01

    In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse…

  • CVE-2018-5756MedJun 16, 2018
    risk 0.31cvss 4.3epss 0.06

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via…

  • CVE-2017-15014MedOct 13, 2017
    risk 0.31cvss 4.3epss 0.05

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an authenticated user uploads…