CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,561)
page 33 of 79| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-44228 | Hig | 0.49 | 7.5 | 0.00 | Oct 28, 2024 | This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data. | ||
| CVE-2024-44100 | Hig | 0.49 | 7.5 | 0.00 | Oct 25, 2024 | Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545. | ||
| CVE-2024-44760 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2024 | Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server. | ||
| CVE-2024-43114 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2024 | In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | ||
| CVE-2023-38370 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197. | ||
| CVE-2024-37038 | Hig | 0.49 | 7.5 | 0.00 | Jun 12, 2024 | CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests. | ||
| CVE-2023-23976 | Hig | 0.49 | 7.5 | 0.00 | Apr 24, 2024 | Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2. | ||
| CVE-2023-52545 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-22889 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2024 | Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request. | ||
| CVE-2023-49338 | Hig | 0.49 | 7.5 | 0.01 | Feb 28, 2024 | Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost. | ||
| CVE-2023-52379 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52362 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-37572 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted. | ||
| CVE-2023-43984 | Hig | 0.49 | 7.5 | 0.01 | Nov 7, 2023 | Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table. | ||
| CVE-2023-42261 | Hig | 0.49 | 7.5 | 0.01 | Sep 21, 2023 | Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication… | ||
| CVE-2023-5042 | Hig | 0.49 | 7.5 | 0.00 | Sep 20, 2023 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575. | ||
| CVE-2023-33966 | Hig | 0.49 | 8.6 | 0.01 | May 31, 2023 | Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies… | ||
| CVE-2023-29731 | Hig | 0.49 | 7.5 | 0.01 | May 30, 2023 | SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application… | ||
| CVE-2023-1693 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2023 | The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-45459 | Hig | 0.49 | 7.5 | 0.00 | May 18, 2023 | Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984. |
- risk 0.49cvss 7.5epss 0.00
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
- risk 0.49cvss 7.5epss 0.00
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
- risk 0.49cvss 7.5epss 0.01
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
- risk 0.49cvss 7.5epss 0.00
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
- risk 0.49cvss 7.5epss 0.01
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
- risk 0.49cvss 7.5epss 0.00
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
- risk 0.49cvss 7.5epss 0.00
Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.01
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
- risk 0.49cvss 7.5epss 0.01
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.
- risk 0.49cvss 7.5epss 0.01
Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
- risk 0.49cvss 7.5epss 0.01
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication…
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.
- risk 0.49cvss 8.6epss 0.01
Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies…
- risk 0.49cvss 7.5epss 0.01
SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application…
- risk 0.49cvss 7.5epss 0.00
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.