VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 65 of 79
  • CVE-2024-58047MedMar 4, 2025
    risk 0.33cvss 5.0epss 0.00

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-52783MedJan 15, 2025
    risk 0.33cvss 5.1epss 0.00

    Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modification of the configuration file.

  • CVE-2024-39544MedOct 11, 2024
    risk 0.33cvss 5.0epss 0.00

    An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker to view NETCONF traceoptions files, representing an exposure of sensitive information. On all Junos OS Evolved…

  • CVE-2024-34648MedSep 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

  • CVE-2024-34616MedAug 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

  • CVE-2024-5321MedJul 18, 2024
    risk 0.33cvss 6.1epss 0.00

    A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.

  • CVE-2024-2819MedJul 2, 2024
    risk 0.33cvss 5.1epss 0.00

    Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.

  • CVE-2024-21615MedApr 12, 2024
    risk 0.33cvss 5.0epss 0.00

    An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access confidential information on the system. On all Junos OS and Junos OS Evolved platforms, when NETCONF traceoptions are configured,…

  • CVE-2024-20841MedMar 5, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

  • CVE-2023-5536MedDec 12, 2023
    risk 0.33cvss 5.0epss 0.00

    A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.

  • CVE-2021-3722MedApr 22, 2022
    risk 0.33cvss 5.0epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to non-standard locations during installation.

  • CVE-2021-32006MedMar 10, 2022
    risk 0.33cvss 5.0epss 0.01

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.

  • CVE-2019-3688MedOct 7, 2019
    risk 0.33cvss 5.1epss 0.00

    The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the…

  • CVE-2019-3689MedSep 19, 2019
    risk 0.33cvss 5.1epss 0.02

    The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and…

  • CVE-2024-41820MedAug 5, 2024
    risk 0.32cvss 6.0epss 0.00

    Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a malicious user can access the worker node which has kubean's deployment, he/she can abuse these excessive permissions to do…

  • CVE-2023-45690MedOct 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's authentication to the OS to read sensitive files on the filesystem

  • CVE-2020-24402MedNov 9, 2020
    risk 0.32cvss 4.9epss 0.02

    Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API…

  • CVE-2019-17103MedJan 27, 2020
    risk 0.32cvss 4.9epss 0.00

    An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read protected directories. This issue affects: Bitdefender AV for Mac versions prior to 8.0.0.

  • CVE-2018-9085MedNov 16, 2018
    risk 0.32cvss 4.9epss 0.01

    A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing Intel Server Platform Services (SPS) and the system Flash…

  • CVE-2025-15615MedMar 27, 2026
    risk 0.31cvss 5.8epss 0.01

    Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers…