VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,582)

page 59 of 80
  • CVE-2023-40076MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.02

    In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-4065MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.

  • CVE-2023-30902MedJun 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations.

  • CVE-2023-32407MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.

  • CVE-2023-32404MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences.

  • CVE-2023-32399MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information.

  • CVE-2023-21104MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:…

  • CVE-2023-28192MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information.

  • CVE-2022-3146MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to…

  • CVE-2022-3101MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to…

  • CVE-2022-1109MedJan 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.

  • CVE-2021-4297MedJan 1, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the file application/controllers/Restapi.php. The manipulation of the argument sourcefilename leads to an unknown weakness. Upgrading…

  • CVE-2022-20448MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2013-4281MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.

  • CVE-2021-46834MedSep 20, 2022
    risk 0.36cvss 5.5epss 0.00

    A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).

  • CVE-2022-27500MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-44470MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-20272MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-22424MedJul 20, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.

  • CVE-2022-2366MedJul 12, 2022
    risk 0.36cvss 5.6epss 0.01

    Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.