VYPR

CWE-277

Insecure Inherited Permissions

VariantDraft

Description

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (74)

page 2 of 4
  • CVE-2023-34391HigAug 31, 2023
    risk 0.48cvss 7.4epss 0.00

    Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more…

  • CVE-2025-37174HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.00

    Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and…

  • CVE-2020-5343HigMay 4, 2020
    risk 0.47cvss 7.3epss 0.00

    Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vulnerability to gain unauthorized access…

  • CVE-2025-58437HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a…

  • CVE-2024-27825HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.

  • CVE-2025-64185MedNov 20, 2025
    risk 0.45cvss epss 0.00

    Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

  • CVE-2025-32092MedFeb 10, 2026
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable…

  • CVE-2025-24327MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack…

  • CVE-2025-3473MedJun 11, 2025
    risk 0.44cvss 6.7epss 0.00

    IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.

  • CVE-2025-20629MedMay 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-29982MedApr 2, 2025
    risk 0.44cvss 6.8epss 0.00

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2024-51448MedJan 18, 2025
    risk 0.44cvss 6.7epss 0.00

    IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any…

  • CVE-2024-36294MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-36276MedNov 13, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-25561MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23908MedAug 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-21835MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-45736MedMay 16, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-33870MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-38541MedJan 19, 2024
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.