CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,561)
page 53 of 79| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-46185 | Med | 0.40 | 6.2 | 0.00 | Oct 24, 2025 | An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames. | ||
| CVE-2025-39201 | Med | 0.40 | 6.1 | 0.00 | Jun 24, 2025 | A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service. | ||
| CVE-2025-49144 | Hig | 0.40 | 7.3 | 0.01 | Jun 23, 2025 | Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker… | ||
| CVE-2025-46587 | Med | 0.40 | 6.2 | 0.00 | May 6, 2025 | Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-20910 | Med | 0.40 | 6.2 | 0.00 | Mar 6, 2025 | Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery. | ||
| CVE-2024-58050 | Med | 0.40 | 6.2 | 0.00 | Mar 4, 2025 | Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-58046 | Med | 0.40 | 6.2 | 0.00 | Mar 4, 2025 | Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-56440 | Med | 0.40 | 6.2 | 0.00 | Jan 8, 2025 | Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2024-54131 | Hig | 0.40 | — | 0.00 | Dec 3, 2024 | The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version… | ||
| CVE-2024-3779 | Med | 0.40 | 6.1 | 0.00 | Jul 16, 2024 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met. | ||
| CVE-2024-35139 | Med | 0.40 | 6.2 | 0.00 | Jun 28, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415. | ||
| CVE-2023-38294 | Med | 0.40 | 6.1 | 0.00 | Apr 22, 2024 | Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell… | ||
| CVE-2024-22085 | Med | 0.40 | 6.2 | 0.00 | Mar 20, 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable. | ||
| CVE-2023-42774 | Med | 0.40 | 6.2 | 0.00 | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions. | ||
| CVE-2023-37878 | Med | 0.40 | 6.1 | 0.00 | Sep 12, 2023 | Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. | ||
| CVE-2023-21513 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. | ||
| CVE-2022-45118 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data… | ||
| CVE-2022-28702 | Med | 0.40 | 6.1 | 0.00 | Jun 2, 2022 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine. | ||
| CVE-2021-33214 | Med | 0.40 | 6.1 | 0.01 | Jul 9, 2021 | In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation. | ||
| CVE-2012-5578 | Med | 0.40 | 6.2 | 0.00 | Nov 25, 2019 | Python keyring has insecure permissions on new databases allowing world-readable files to be created |
- risk 0.40cvss 6.2epss 0.00
An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.
- risk 0.40cvss 6.1epss 0.00
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.
- risk 0.40cvss 7.3epss 0.01
Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker…
- risk 0.40cvss 6.2epss 0.00
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.40cvss —epss 0.00
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version…
- risk 0.40cvss 6.1epss 0.00
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
- risk 0.40cvss 6.2epss 0.00
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
- risk 0.40cvss 6.1epss 0.00
Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell…
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.
- risk 0.40cvss 6.2epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.
- risk 0.40cvss 6.1epss 0.00
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
- risk 0.40cvss 6.1epss 0.00
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
- risk 0.40cvss 6.2epss 0.00
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data…
- risk 0.40cvss 6.1epss 0.00
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
- risk 0.40cvss 6.1epss 0.01
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
- risk 0.40cvss 6.2epss 0.00
Python keyring has insecure permissions on new databases allowing world-readable files to be created