VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 35 of 79
  • CVE-2021-44858HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.

  • CVE-2021-37030HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-22368HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.

  • CVE-2021-22371HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-21737HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.01

    A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10…

  • CVE-2020-21342HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.

  • CVE-2020-27569HigApr 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.

  • CVE-2020-23971HigSep 1, 2020
    risk 0.49cvss 7.5epss 0.02

    gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the…

  • CVE-2020-2077HigJul 29, 2020
    risk 0.49cvss 7.5epss 0.01

    SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.

  • CVE-2019-9943HigJun 17, 2020
    risk 0.49cvss 7.5epss 0.01

    In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.

  • CVE-2020-13894HigJun 7, 2020
    risk 0.49cvss 7.5epss 0.01

    handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.

  • CVE-2017-18669HigApr 7, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017).

  • CVE-2017-18668HigApr 7, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017).

  • CVE-2019-3944HigApr 1, 2020
    risk 0.49cvss 7.5epss 0.02

    Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.

  • CVE-2020-7943HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.08

    Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as…

  • CVE-2020-7972HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

  • CVE-2010-5108HigNov 13, 2019
    risk 0.49cvss 7.5epss 0.01

    Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.

  • CVE-2012-5577HigOct 28, 2019
    risk 0.49cvss 7.5epss 0.02

    Python keyring lib before 0.10 created keyring files with world-readable permissions.

  • CVE-2019-16106HigSep 10, 2019
    risk 0.49cvss 7.5epss 0.01

    The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

  • CVE-2019-9630HigJul 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.