VYPR

CWE-277

Insecure Inherited Permissions

VariantDraft

Description

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (74)

page 3 of 4
  • CVE-2023-39230MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34997MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34314MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41700MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33898MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28658MedAug 11, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-46656MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41687MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41658MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-38103MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access

  • CVE-2022-36377MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-31332MedApr 8, 2025
    risk 0.43cvss 6.6epss 0.00

    Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability.…

  • CVE-2026-44836MedMay 26, 2026
    risk 0.42cvss 6.5epss 0.00

    view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls it with public_send. The code does not verify that the requested method is one…

  • CVE-2025-56019MedOct 2, 2025
    risk 0.42cvss 6.5epss 0.00

    An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legitimate applications are…

  • CVE-2025-36104MedJul 12, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protocol.

  • CVE-2025-11554MedOct 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited…

  • CVE-2024-36691MedJun 12, 2024
    risk 0.41cvss 6.3epss 0.00

    Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.

  • CVE-2025-22448MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2026-20630MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.

  • CVE-2023-28207MedMar 21, 2025
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.