CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,267)
page 92 of 164| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23990 | Hig | 0.49 | 7.6 | 0.01 | May 17, 2024 | Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0. | ||
| CVE-2024-0097 | Hig | 0.49 | 7.5 | 0.00 | May 14, 2024 | NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerability might lead to information disclosure,… | ||
| CVE-2024-0096 | Hig | 0.49 | 7.5 | 0.00 | May 14, 2024 | NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to information disclosure, escalation of… | ||
| CVE-2024-33398 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2024 | There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the… | ||
| CVE-2023-52716 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2024 | Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-1764 | Hig | 0.49 | 7.6 | 0.00 | Mar 5, 2024 | Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances | ||
| CVE-2024-25842 | Hig | 0.49 | 7.5 | 0.01 | Mar 3, 2024 | An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess… | ||
| CVE-2024-21985 | Hig | 0.49 | 7.6 | 0.00 | Jan 26, 2024 | ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege.… | ||
| CVE-2023-52105 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-52116 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device. | ||
| CVE-2023-52114 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2023-52107 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-41138 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2023 | The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process. | ||
| CVE-2023-46758 | Hig | 0.49 | 7.5 | 0.00 | Nov 8, 2023 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device. | ||
| CVE-2023-5978 | Hig | 0.49 | 7.5 | 0.01 | Nov 8, 2023 | In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints. When only a list of resolvable domain names was specified… | ||
| CVE-2023-46771 | Hig | 0.49 | 7.5 | 0.00 | Nov 8, 2023 | Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-4607 | Hig | 0.49 | 7.5 | 0.00 | Oct 25, 2023 | An authenticated XCC user can change permissions for any user through a crafted API command. | ||
| CVE-2023-41309 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39375 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges | ||
| CVE-2023-41301 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally. |
- risk 0.49cvss 7.6epss 0.01
Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.
- risk 0.49cvss 7.5epss 0.00
NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerability might lead to information disclosure,…
- risk 0.49cvss 7.5epss 0.00
NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to information disclosure, escalation of…
- risk 0.49cvss 7.5epss 0.01
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the…
- risk 0.49cvss 7.5epss 0.00
Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.6epss 0.00
Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess…
- risk 0.49cvss 7.6epss 0.00
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege.…
- risk 0.49cvss 7.5epss 0.00
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
- risk 0.49cvss 7.5epss 0.00
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.
- risk 0.49cvss 7.5epss 0.00
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
- risk 0.49cvss 7.5epss 0.01
In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints. When only a list of resolvable domain names was specified…
- risk 0.49cvss 7.5epss 0.00
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
An authenticated XCC user can change permissions for any user through a crafted API command.
- risk 0.49cvss 7.5epss 0.01
Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
- risk 0.49cvss 7.5epss 0.00
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.