VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 11 of 79
  • CVE-2012-4434HigJan 9, 2020
    risk 0.57cvss 8.8epss 0.03

    fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.

  • CVE-2019-19202HigNov 21, 2019
    risk 0.57cvss 8.8epss 0.01

    In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.

  • CVE-2015-9477HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.

  • CVE-2015-9476HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.

  • CVE-2015-9475HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.

  • CVE-2015-9474HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.

  • CVE-2019-17383CriOct 9, 2019
    risk 0.57cvss 9.8epss 0.02

    The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.

  • CVE-2019-9679HigSep 18, 2019
    risk 0.57cvss 8.8epss 0.01

    Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for…

  • CVE-2019-12450CriMay 29, 2019
    risk 0.57cvss 9.8epss 0.03

    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

  • CVE-2018-10605HigOct 1, 2018
    risk 0.57cvss 8.8epss 0.01

    Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU.

  • CVE-2018-10604HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.02

    SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution.

  • CVE-2017-16522HigNov 3, 2017
    risk 0.57cvss 8.8epss 0.03

    MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by specifying /bin/sh as the command to execute.

  • CVE-2017-12230HigSep 29, 2017
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using…

  • CVE-2025-44643HigAug 4, 2025
    risk 0.56cvss 8.6epss 0.00

    Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the password property in the ripd.conf configuration file sets a hardcoded weak password, posing a security risk. An attacker with…

  • CVE-2023-2749HigMay 31, 2023
    risk 0.56cvss 8.6epss 0.00

    Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. Download Center on ADM 4.0 and above will be…

  • CVE-2013-4859HigDec 27, 2019
    risk 0.56cvss 8.1epss 0.07

    INSTEON Hub 2242-222 lacks Web and API authentication

  • CVE-2018-11454HigAug 7, 2018
    risk 0.56cvss 8.6epss 0.00

    A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions…

  • CVE-2018-25359HigMay 25, 2026
    risk 0.55cvss 8.4epss 0.00

    Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a…

  • CVE-2026-0432HigMay 15, 2026
    risk 0.55cvss epss 0.00

    Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.

  • CVE-2026-0539HigApr 22, 2026
    risk 0.55cvss epss 0.00

    Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting the service binary with arbitrary contents. This service binary is automatically launched with NT\SYSTEM privileges on boot. This…