VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 49 of 80
  • CVE-2025-15341MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an incorrect default permissions vulnerability in Benchmark.

  • CVE-2025-15340MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an incorrect default permissions vulnerability in Comply.

  • CVE-2025-15339MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an incorrect default permissions vulnerability in Discover.

  • CVE-2025-15338MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

  • CVE-2025-15337MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an incorrect default permissions vulnerability in Patch.

  • CVE-2025-15336MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Tanium addressed an incorrect default permissions vulnerability in Performance.

  • CVE-2025-57850MedDec 2, 2025
    risk 0.42cvss 6.4epss 0.00

    A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected…

  • CVE-2025-43507MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.

  • CVE-2025-57848MedOct 23, 2025
    risk 0.42cvss 6.4epss 0.00

    A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an…

  • CVE-2025-58712MedOct 22, 2025
    risk 0.42cvss 6.4epss 0.00

    A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

  • CVE-2025-57852MedSep 30, 2025
    risk 0.42cvss 6.4epss 0.00

    A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected…

  • CVE-2025-7195MedAug 7, 2025
    risk 0.42cvss 6.4epss 0.00

    Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time.…

  • CVE-2024-55398MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.

  • CVE-2025-41665MedJul 8, 2025
    risk 0.42cvss 6.5epss 0.00

    An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.

  • CVE-2024-54564MedMar 21, 2025
    risk 0.42cvss 6.5epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file received from AirDrop may not have the quarantine flag applied.

  • CVE-2024-45690HigNov 20, 2024
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

  • CVE-2024-48293MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.

  • CVE-2024-52926MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

  • CVE-2024-10469MedOct 28, 2024
    risk 0.42cvss 6.5epss 0.00

    VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.

  • CVE-2024-38222MedSep 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability