VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 8 of 79
  • CVE-2024-8533HigSep 12, 2024
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

  • CVE-2024-6974HigJul 31, 2024
    risk 0.57cvss 8.8epss 0.00

    Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

  • CVE-2024-36541HigJul 24, 2024
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2024-6148HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

  • CVE-2024-3904HigJul 4, 2024
    risk 0.57cvss 8.8epss 0.00

    Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute arbitrary code by saving a malicious file to a specific folder. As a result, the attacker…

  • CVE-2024-34221HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

  • CVE-2024-28056CriApr 15, 2024
    risk 0.57cvss 9.8epss 0.02

    Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and…

  • CVE-2021-3187HigDec 11, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5,…

  • CVE-2023-47250HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control…

  • CVE-2023-48648CriNov 17, 2023
    risk 0.57cvss 9.8epss 0.01

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can…

  • CVE-2023-23583HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.02

    Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

  • CVE-2023-4664HigSep 15, 2023
    risk 0.57cvss 8.8epss 0.01

    Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.

  • CVE-2023-31462HigJul 20, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writable for all users on the computer, in order to trigger code execution with higher privileges.

  • CVE-2023-32221HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.00

    EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation.

  • CVE-2022-30759HigMay 2, 2023
    risk 0.57cvss 8.8epss 0.01

    In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.

  • CVE-2021-23166HigApr 25, 2023
    risk 0.57cvss 8.7epss 0.01

    A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.

  • CVE-2023-22951HigApr 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all…

  • CVE-2020-21514HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.

  • CVE-2023-25355HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.03

    CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on a sipXcom server can overwrite a service file, and escalate their privileges to `root`.

  • CVE-2021-34164HigFeb 17, 2023
    risk 0.57cvss 8.8epss 0.01

    Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location.