VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 34 of 79
  • CVE-2023-1809HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.01

    The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.

  • CVE-2022-48360HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-45552HigMar 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.

  • CVE-2022-45454HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2022-46761HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.

  • CVE-2022-44561HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.

  • CVE-2022-44557HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-44554HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.

  • CVE-2022-43574HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.00

    "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."

  • CVE-2022-32743HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

  • CVE-2022-37006HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.

  • CVE-2022-33023HigJun 29, 2022
    risk 0.49cvss 7.5epss 0.01

    CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.

  • CVE-2022-23802HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private…

  • CVE-2022-29585HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

  • CVE-2022-29547HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.01

    The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.

  • CVE-2021-40049HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.

  • CVE-2021-41652HigMar 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

  • CVE-2021-46086HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in…

  • CVE-2021-40004HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-39967HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.