VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 44 of 79
  • CVE-2024-35287MedOct 21, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary…

  • CVE-2023-42133MedOct 11, 2024
    risk 0.44cvss 6.7epss 0.00

    PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version…

  • CVE-2024-26025MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23974MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23495MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-22378MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-43747MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-38459HigJun 16, 2024
    risk 0.44cvss 7.8epss 0.00

    langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

  • CVE-2024-27180MedJun 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

  • CVE-2023-42668MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-42433MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-34011MedApr 29, 2024
    risk 0.44cvss 6.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758.

  • CVE-2024-2859MedApr 27, 2024
    risk 0.44cvss 6.8epss 0.01

    By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attacker should they gain access to the root account.

  • CVE-2024-25958MedMar 26, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data,…

  • CVE-2023-28389MedMar 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-49721MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

  • CVE-2023-41231MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40154MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local access.

  • CVE-2023-34315MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28739MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.