VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 34 of 80
  • CVE-2023-49338HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

  • CVE-2023-52379HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52362HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-37572HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.

  • CVE-2023-43984HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.

  • CVE-2023-42261HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication…

  • CVE-2023-5042HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2023-33966HigMay 31, 2023
    risk 0.49cvss 8.6epss 0.01

    Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies…

  • CVE-2023-29731HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application…

  • CVE-2023-1693HigMay 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-45459HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2023-1809HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.01

    The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.

  • CVE-2022-48360HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-45552HigMar 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.

  • CVE-2022-45454HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2022-46761HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.

  • CVE-2022-44561HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.

  • CVE-2022-44557HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-44554HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.

  • CVE-2022-43574HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.00

    "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."