VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 47 of 80
  • CVE-2020-25593MedJul 15, 2021
    risk 0.44cvss 6.7epss 0.00

    Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.

  • CVE-2021-31998MedJun 10, 2021
    risk 0.44cvss 6.8epss 0.00

    A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux…

  • CVE-2020-22475MedFeb 22, 2021
    risk 0.44cvss 6.8epss 0.00

    "Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application component allows arbitrary applications on a device to add tasks with no restrictions.

  • CVE-2020-8765MedFeb 17, 2021
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-8701MedFeb 17, 2021
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-28044MedNov 2, 2020
    risk 0.44cvss 6.8epss 0.00

    An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB service, and then list, read, create, and overwrite files with MAINAPP permissions.

  • CVE-2019-14718MedOct 23, 2020
    risk 0.44cvss 6.7epss 0.01

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.

  • CVE-2020-13468MedAug 31, 2020
    risk 0.44cvss 6.8epss 0.01

    Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).

  • CVE-2020-3152MedAug 26, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissions that are configured by default on an…

  • CVE-2020-0122MedJul 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed…

  • CVE-2020-14019HigJun 19, 2020
    risk 0.44cvss 7.8epss 0.00

    Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

  • CVE-2018-21061MedApr 8, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical functions in the locked state. The Samsung ID is SVE-2016-6341 (August 2018).

  • CVE-2019-19792MedMar 3, 2020
    risk 0.44cvss 6.7epss 0.00

    A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by appending data to root-owned files.

  • CVE-2019-14510MedOct 11, 2019
    risk 0.44cvss 6.7epss 0.01

    An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdminxxxxxxxxx (e.g., FSAdmin123456789) on the server that hosts the LAN Cache and all clients that are assigned to a LAN Cache. This…

  • CVE-2019-12670MedSep 25, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device. The vulnerability is due to insufficient file permissions. An attacker could…

  • CVE-2019-7588MedJun 18, 2019
    risk 0.44cvss 6.7epss 0.01

    A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be achieved. This vulnerability impacts exacqVision ESM v5.12.2 and all prior versions of ESM running on a Windows operating system.…

  • CVE-2019-12795HigJun 11, 2019
    risk 0.44cvss 7.8epss 0.00

    daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note…

  • CVE-2026-18273MedAug 20, 2026
    risk 0.43cvss 6.6epss 0.00

    Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to…

  • CVE-2025-8421MedNov 12, 2025
    risk 0.43cvss 6.6epss 0.00

    An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.

  • CVE-2024-32978MedMay 27, 2024
    risk 0.43cvss 6.6epss 0.01

    Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecure file permissions has been identified in the Kaminari pagination library for Ruby on Rails, concerning insecure file permissions. This vulnerability is of…