VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 49 of 79
  • CVE-2024-48293MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.

  • CVE-2024-52926MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

  • CVE-2024-10469MedOct 28, 2024
    risk 0.42cvss 6.5epss 0.00

    VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.

  • CVE-2024-38222MedSep 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2024-6325MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advis…

  • CVE-2024-34455HigMay 3, 2024
    risk 0.42cvss 7.5epss 0.01

    Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.

  • CVE-2023-28870MedDec 9, 2023
    risk 0.42cvss 6.5epss 0.01

    Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.

  • CVE-2023-47335MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones.

  • CVE-2023-4091MedNov 3, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client…

  • CVE-2023-38334MedJul 20, 2023
    risk 0.42cvss 6.5epss 0.01

    Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked…

  • CVE-2023-30281MedMay 16, 2023
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for PrestaShop, a guest can access exports from the module which can lead to leak of personnal informations from ps_customer table…

  • CVE-2023-27035MedMay 1, 2023
    risk 0.42cvss 6.5epss 0.02

    An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

  • CVE-2023-29058MedApr 28, 2023
    risk 0.42cvss 6.4epss 0.00

    A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

  • CVE-2022-47551MedDec 20, 2022
    risk 0.42cvss 6.5epss 0.01

    Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman…

  • CVE-2022-42446MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.

  • CVE-2022-2528MedSep 9, 2022
    risk 0.42cvss 6.5epss 0.00

    In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.

  • CVE-2022-31251MedSep 7, 2022
    risk 0.42cvss 6.5epss 0.00

    A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.

  • CVE-2021-39087MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.

  • CVE-2022-30375MedMay 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.

  • CVE-2022-30367MedMay 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.