VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 1 of 79
  • CVE-2013-0632CriKEVJan 17, 2013
    risk 0.86cvss 9.8epss 0.94

    administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web…

  • CVE-2019-17124CriOct 9, 2019
    risk 0.69cvss 9.8epss 0.23

    Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

  • CVE-1999-0426CriMar 1, 1999
    risk 0.68cvss 9.8epss 0.11

    The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

  • CVE-2023-31068CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.

  • CVE-2023-31067CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.

  • CVE-2023-26918CriApr 14, 2023
    risk 0.67cvss 9.8epss 0.06

    Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

  • CVE-2017-11610HigAug 23, 2017
    risk 0.67cvss 8.8epss 0.87

    The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

  • CVE-2024-57684CriJan 16, 2025
    risk 0.65cvss 9.8epss 0.14

    An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

  • CVE-2022-42150CriOct 19, 2023
    risk 0.65cvss 10.0epss 0.01

    TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.

  • CVE-2021-3437CriDec 12, 2022
    risk 0.65cvss 9.8epss 0.16

    Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. HP is releasing software updates to mitigate the potential vulnerabilities.

  • CVE-2020-29492CriJan 4, 2021
    risk 0.65cvss 10.0epss 0.02

    Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.

  • CVE-2020-29491CriJan 4, 2021
    risk 0.65cvss 10.0epss 0.02

    Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise…

  • CVE-2020-12834CriMay 15, 2020
    risk 0.65cvss 9.8epss 0.11

    eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during…

  • CVE-2019-19896CriJan 23, 2020
    risk 0.65cvss 9.9epss 0.03

    In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the…

  • CVE-2020-37129CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting…

  • CVE-2025-60262CriJan 6, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root…

  • CVE-2025-8031CriJul 22, 2025
    risk 0.64cvss 9.8epss 0.00

    The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird…

  • CVE-2014-7210CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.00

    pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.

  • CVE-2025-6179CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and…

  • CVE-2025-40585CriJun 10, 2025
    risk 0.64cvss 9.9epss 0.00

    A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.