VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 10 of 79
  • CVE-2021-39273HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.03

    In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges.

  • CVE-2020-5353HigJul 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive…

  • CVE-2021-28271HigApr 27, 2021
    risk 0.57cvss 8.8epss 0.02

    Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for…

  • CVE-2020-13555HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM…

  • CVE-2020-13553HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to…

  • CVE-2020-13552HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or…

  • CVE-2020-13551HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.00

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM…

  • CVE-2020-13541HigJan 5, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Depending on the vector chosen, an attacker can overwrite the service executable and execute arbitrary code with System privileges or…

  • CVE-2020-11955HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.

  • CVE-2017-18915CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.

  • CVE-2020-12075HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.01

    The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

  • CVE-2020-6439HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

  • CVE-2020-7004HigApr 3, 2020
    risk 0.57cvss 8.8epss 0.00

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.

  • CVE-2020-5551HigMar 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA…

  • CVE-2019-16061HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.01

    A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low privileged user with access to the system to read sensitive data (e.g., .htpasswd) and create/modify/delete content (e.g., under…

  • CVE-2014-2723HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.02

    In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an…

  • CVE-2014-2722HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.02

    In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an…

  • CVE-2014-2721HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.02

    In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an…

  • CVE-2020-9408HigMar 11, 2020
    risk 0.57cvss 8.8epss 0.01

    The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permissions to the Spotfire Library, but not "Script Author" group…

  • CVE-2019-19475HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can…