VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 58 of 79
  • CVE-2022-22424MedJul 20, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.

  • CVE-2022-2366MedJul 12, 2022
    risk 0.36cvss 5.6epss 0.01

    Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.

  • CVE-2022-25804MedJun 9, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKEY_LOCAL_MACHINE\SOFTWARE) allow an unprivileged local attacker to read the encrypted dbuser and…

  • CVE-2022-30747MedJun 7, 2022
    risk 0.36cvss 5.5epss 0.00

    PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.

  • CVE-2022-28218MedApr 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).

  • CVE-2022-26855MedApr 8, 2022
    risk 0.36cvss 5.5epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service.

  • CVE-2021-39779MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39770MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39769MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39748MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39747MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-25815MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2022-25814MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2021-44216MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.

  • CVE-2021-44215MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.

  • CVE-2021-20269MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects…

  • CVE-2021-37103MedFeb 25, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2022-23922MedFeb 24, 2022
    risk 0.36cvss 5.6epss 0.00

    WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer directory and elevate permissions whenever the program is executed.

  • CVE-2022-23104MedFeb 24, 2022
    risk 0.36cvss 5.6epss 0.00

    WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Workspace directory, which holds DLL files and executables. A low-privilege attacker could write a malicious DLL file to the Operator…

  • CVE-2021-33166MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable information disclosure via local access.