VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 33 of 80
  • CVE-2017-18868HigMay 21, 2020
    risk 0.50cvss 7.7epss 0.01

    Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built.

  • CVE-2025-68825HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.

  • CVE-2025-59030HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.01

    An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

  • CVE-2025-13025HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

  • CVE-2025-54530HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

  • CVE-2025-30706HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2024-55950HigDec 26, 2024
    risk 0.49cvss —epss 0.00

    Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential security vulnerabilities. The application…

  • CVE-2024-49202HigDec 18, 2024
    risk 0.49cvss 7.6epss 0.00

    Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.

  • CVE-2024-44786HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

  • CVE-2024-28058HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.00

    In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.

  • CVE-2024-36063HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.00

    The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component.

  • CVE-2024-44228HigOct 28, 2024
    risk 0.49cvss 7.5epss 0.00

    This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.

  • CVE-2024-44100HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

  • CVE-2024-44760HigAug 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.

  • CVE-2024-43114HigAug 6, 2024
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

  • CVE-2023-38370HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

  • CVE-2024-37038HigJun 12, 2024
    risk 0.49cvss 7.5epss 0.00

    CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

  • CVE-2023-23976HigApr 24, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.

  • CVE-2023-52545HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-22889HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.