VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 24 of 79
  • CVE-2022-20435HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android SoCAndroid ID: A-242248367

  • CVE-2022-26235HigOct 6, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate executables and libraries that run as the elevated SYSTEM…

  • CVE-2022-3263HigSep 23, 2022
    risk 0.51cvss 7.8epss 0.00

    The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.

  • CVE-2022-38764HigSep 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.

  • CVE-2022-38466HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.

  • CVE-2022-2735HigSep 6, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster"…

  • CVE-2022-37173HigAug 30, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.

  • CVE-2022-26344HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-30490HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.

  • CVE-2022-20246HigAug 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-37030HigAug 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM module.

  • CVE-2022-33912HigJun 17, 2022
    risk 0.51cvss 7.8epss 0.00

    A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/…

  • CVE-2022-31500HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.00

    In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.

  • CVE-2022-29483HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

  • CVE-2022-20732HigApr 21, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker to access confidential information and elevate privileges on an affected device. This vulnerability is due to improper access…

  • CVE-2021-39794HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-39780HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-1033HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-1000HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-26839HigMar 29, 2022
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.