VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 61 of 80
  • CVE-2021-1831MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to access restricted files.

  • CVE-2021-30750MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.

  • CVE-2021-31007MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11.6.2, watchOS 8.1, macOS Monterey 12.1. A malicious application may be able to bypass Privacy preferences.

  • CVE-2021-31006MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicious application may be able to bypass certain Privacy preferences.

  • CVE-2021-22295MedAug 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

  • CVE-2021-20490MedJun 29, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.

  • CVE-2020-9451MedMay 25, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet…

  • CVE-2021-3451MedApr 27, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.

  • CVE-2021-30494MedApr 14, 2021
    risk 0.36cvss 5.5epss 0.01

    Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log…

  • CVE-2021-30493MedApr 14, 2021
    risk 0.36cvss 5.5epss 0.01

    Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log…

  • CVE-2021-3462MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.

  • CVE-2021-25381MedApr 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2021-25355MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.00

    Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2021-0381MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-8357MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.

  • CVE-2021-24031MedMar 4, 2021
    risk 0.36cvss 5.5epss 0.00

    In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

  • CVE-2020-0524MedFeb 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-26941MedJan 26, 2021
    risk 0.36cvss 5.5epss 0.00

    A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place…

  • CVE-2020-24460MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-26088MedSep 24, 2020
    risk 0.36cvss 5.5epss 0.00

    A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.