VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 39 of 80
  • CVE-2023-31349HigAug 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-46870HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.00

    extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python…

  • CVE-2024-32368HigApr 22, 2024
    risk 0.47cvss 7.3epss 0.00

    Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via the Bluetooth Low Energy (BLE) component.

  • CVE-2024-0259HigMar 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a…

  • CVE-2023-38960HigFeb 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.

  • CVE-2023-3116HigNov 20, 2023
    risk 0.47cvss 7.3epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.

  • CVE-2023-46743HigNov 9, 2023
    risk 0.47cvss 7.3epss 0.01

    application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on the rights that a user has over a document, they should be able to open the office attachments files in view or edit mode. Currently, if a user opens an…

  • CVE-2023-4706HigNov 8, 2023
    risk 0.47cvss 7.3epss 0.00

    A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.

  • CVE-2023-29057HigApr 28, 2023
    risk 0.47cvss 7.3epss 0.01

    A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First,…

  • CVE-2022-3884HigFeb 28, 2023
    risk 0.47cvss 7.3epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local users to read and write specific files.This issue affects Hitachi Ops Center Analyzer: from 10.9.0-00 before 10.9.0-01.

  • CVE-2022-36397HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33196HigFeb 16, 2023
    risk 0.47cvss 7.2epss 0.00

    Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-37289HigAug 22, 2022
    risk 0.47cvss 7.2epss 0.02

    Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.

  • CVE-2021-0441HigJul 14, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-21736HigJun 10, 2021
    risk 0.47cvss 7.2epss 0.01

    A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera,…

  • CVE-2021-31519HigMay 12, 2021
    risk 0.47cvss 7.3epss 0.00

    An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an…

  • CVE-2021-28649HigMay 12, 2021
    risk 0.47cvss 7.3epss 0.00

    An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator…

  • CVE-2021-0246HigApr 22, 2021
    risk 0.47cvss 7.3epss 0.00

    On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services on Juniper Networks Junos OS, due to incorrect default permissions assigned to tenant system administrators a tenant system administrator may inadvertently send their network…

  • CVE-2021-0235HigApr 22, 2021
    risk 0.47cvss 7.3epss 0.00

    On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Juniper Networks Junos OS, due to incorrect permission scheme assigned to tenant system administrators, a tenant system administrator may inadvertently send their…

  • CVE-2021-22311HigMar 22, 2021
    risk 0.47cvss 7.2epss 0.01

    There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected…