VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 92 of 164
  • CVE-2023-23990HigMay 17, 2024
    risk 0.49cvss 7.6epss 0.01

    Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.

  • CVE-2024-0097HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.00

    NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerability might lead to information disclosure,…

  • CVE-2024-0096HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.00

    NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to information disclosure, escalation of…

  • CVE-2024-33398HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the…

  • CVE-2023-52716HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-1764HigMar 5, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances

  • CVE-2024-25842HigMar 3, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess…

  • CVE-2024-21985HigJan 26, 2024
    risk 0.49cvss 7.6epss 0.00

    ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege.…

  • CVE-2023-52105HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-52116HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

  • CVE-2023-52114HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2023-52107HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-41138HigNov 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.

  • CVE-2023-46758HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

  • CVE-2023-5978HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints.  When only a list of resolvable domain names was specified…

  • CVE-2023-46771HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.00

    Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-4607HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.00

    An authenticated XCC user can change permissions for any user through a crafted API command.

  • CVE-2023-41309HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-39375HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges

  • CVE-2023-41301HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.