VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 4 of 79
  • CVE-2023-23566CriJan 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification…

  • CVE-2022-27773CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.03

    A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

  • CVE-2022-44929CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

  • CVE-2022-34824CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote…

  • CVE-2022-40109CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.

  • CVE-2022-36640CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.02

    influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly…

  • CVE-2022-25899CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-37003CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.00

    The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.

  • CVE-2022-32207CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.07

    When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the…

  • CVE-2022-28932CriMay 23, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

  • CVE-2022-27919CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.

  • CVE-2021-20001CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.

  • CVE-2021-39658CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system…

  • CVE-2021-46093CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.01

    eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

  • CVE-2021-45003CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.03

    Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.

  • CVE-2021-36990CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

  • CVE-2021-36989CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

  • CVE-2021-36365CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

  • CVE-2021-36363CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

  • CVE-2021-39274CriAug 19, 2021
    risk 0.64cvss 9.8epss 0.03

    In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file. This results in arbitrary code execution with root privileges.