VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 54 of 80
  • CVE-2025-20910MedMar 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

  • CVE-2024-58050MedMar 4, 2025
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-58046MedMar 4, 2025
    risk 0.40cvss 6.2epss 0.00

    Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-56440MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-54131HigDec 3, 2024
    risk 0.40cvss —epss 0.00

    The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version…

  • CVE-2024-3779MedJul 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.

  • CVE-2024-35139MedJun 28, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.

  • CVE-2023-38294MedApr 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell…

  • CVE-2024-22085MedMar 20, 2024
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.

  • CVE-2023-42774MedNov 20, 2023
    risk 0.40cvss 6.2epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.

  • CVE-2023-37878MedSep 12, 2023
    risk 0.40cvss 6.1epss 0.01

    Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

  • CVE-2023-21513MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.

  • CVE-2022-45118MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data…

  • CVE-2022-28702MedJun 2, 2022
    risk 0.40cvss 6.1epss 0.00

    Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

  • CVE-2021-33214MedJul 9, 2021
    risk 0.40cvss 6.1epss 0.01

    In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.

  • CVE-2012-5578MedNov 25, 2019
    risk 0.40cvss 6.2epss 0.00

    Python keyring has insecure permissions on new databases allowing world-readable files to be created

  • CVE-2019-12752MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.00

    The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.

  • CVE-2019-16186HigSep 9, 2019
    risk 0.40cvss 7.2epss 0.01

    In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.

  • CVE-2019-16185HigSep 9, 2019
    risk 0.40cvss 7.2epss 0.01

    In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.

  • CVE-2019-3870MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only…