CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,581)
page 54 of 80| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20910 | Med | 0.40 | 6.2 | 0.00 | Mar 6, 2025 | Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery. | ||
| CVE-2024-58050 | Med | 0.40 | 6.2 | 0.00 | Mar 4, 2025 | Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-58046 | Med | 0.40 | 6.2 | 0.00 | Mar 4, 2025 | Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-56440 | Med | 0.40 | 6.2 | 0.00 | Jan 8, 2025 | Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2024-54131 | Hig | 0.40 | — | 0.00 | Dec 3, 2024 | The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version… | ||
| CVE-2024-3779 | Med | 0.40 | 6.1 | 0.00 | Jul 16, 2024 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met. | ||
| CVE-2024-35139 | Med | 0.40 | 6.2 | 0.00 | Jun 28, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415. | ||
| CVE-2023-38294 | Med | 0.40 | 6.1 | 0.00 | Apr 22, 2024 | Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell… | ||
| CVE-2024-22085 | Med | 0.40 | 6.2 | 0.00 | Mar 20, 2024 | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable. | ||
| CVE-2023-42774 | Med | 0.40 | 6.2 | 0.00 | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions. | ||
| CVE-2023-37878 | Med | 0.40 | 6.1 | 0.01 | Sep 12, 2023 | Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. | ||
| CVE-2023-21513 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. | ||
| CVE-2022-45118 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data… | ||
| CVE-2022-28702 | Med | 0.40 | 6.1 | 0.00 | Jun 2, 2022 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine. | ||
| CVE-2021-33214 | Med | 0.40 | 6.1 | 0.01 | Jul 9, 2021 | In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation. | ||
| CVE-2012-5578 | Med | 0.40 | 6.2 | 0.00 | Nov 25, 2019 | Python keyring has insecure permissions on new databases allowing world-readable files to be created | ||
| CVE-2019-12752 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2019 | The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system. | ||
| CVE-2019-16186 | Hig | 0.40 | 7.2 | 0.01 | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions. | ||
| CVE-2019-16185 | Hig | 0.40 | 7.2 | 0.01 | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions. | ||
| CVE-2019-3870 | Med | 0.40 | 6.1 | 0.01 | Apr 9, 2019 | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only… |
- risk 0.40cvss 6.2epss 0.00
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.40cvss —epss 0.00
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version…
- risk 0.40cvss 6.1epss 0.00
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
- risk 0.40cvss 6.2epss 0.00
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
- risk 0.40cvss 6.1epss 0.00
Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell…
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.
- risk 0.40cvss 6.2epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.
- risk 0.40cvss 6.1epss 0.01
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
- risk 0.40cvss 6.1epss 0.00
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
- risk 0.40cvss 6.2epss 0.00
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data…
- risk 0.40cvss 6.1epss 0.00
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
- risk 0.40cvss 6.1epss 0.01
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
- risk 0.40cvss 6.2epss 0.00
Python keyring has insecure permissions on new databases allowing world-readable files to be created
- risk 0.40cvss 6.1epss 0.00
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.
- risk 0.40cvss 7.2epss 0.01
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
- risk 0.40cvss 7.2epss 0.01
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
- risk 0.40cvss 6.1epss 0.01
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only…