VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 93 of 164
  • CVE-2023-32457HigAug 29, 2023
    risk 0.49cvss 7.5epss 0.00

    Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-32559HigAug 24, 2023
    risk 0.49cvss 7.5epss 0.02

    A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of…

  • CVE-2021-35309HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

  • CVE-2022-48515HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-25521HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed. A successful exploit of this vulnerability may lead to denial of…

  • CVE-2023-33966HigMay 31, 2023
    risk 0.49cvss 8.6epss 0.01

    Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies…

  • CVE-2023-1694HigMay 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-1693HigMay 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-29350HigMay 5, 2023
    risk 0.49cvss 7.5epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-48286HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-4441HigJan 31, 2023
    risk 0.49cvss 7.6epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.

  • CVE-2023-22331HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information.

  • CVE-2022-0222HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80…

  • CVE-2021-34579HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web…

  • CVE-2022-39422HigOct 18, 2022
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2022-3079HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.

  • CVE-2021-0891HigAug 24, 2022
    risk 0.49cvss 7.5epss 0.00

    An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Android SoCAndroid ID: A-236849490

  • CVE-2022-23720HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.00

    PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by…

  • CVE-2022-22390HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.

  • CVE-2022-22257HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.