VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 10 of 18
  • CVE-2024-50924MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.

  • CVE-2024-50921MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.

  • CVE-2024-29080MedJul 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

  • CVE-2023-52542MedApr 8, 2024
    risk 0.42cvss 6.5epss 0.00

    Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-45859HigFeb 28, 2024
    risk 0.42cvss 7.6epss 0.01

    In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.

  • CVE-2021-22382MedJun 22, 2021
    risk 0.42cvss 6.5epss 0.00

    Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and log in to a PC to induce a user to install a specially crafted application. After successfully exploiting this vulnerability, the attacker can perform…

  • CVE-2021-21735MedJun 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N…

  • CVE-2021-3418MedMar 15, 2021
    risk 0.42cvss 6.4epss 0.00

    If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw…

  • CVE-2020-12353MedNov 12, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access.

  • CVE-2020-6564MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

  • CVE-2019-15621MedFeb 4, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.

  • CVE-2019-11748MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This…

  • CVE-2025-8325MedMay 11, 2026
    risk 0.41cvss 6.3epss 0.00

    The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing…

  • CVE-2024-0674MedJan 30, 2024
    risk 0.41cvss 6.3epss 0.00

    Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause…

  • CVE-2022-24428MedApr 8, 2022
    risk 0.41cvss 6.3epss 0.01

    Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and…

  • CVE-2020-16910MedOct 16, 2020
    risk 0.41cvss 6.2epss 0.03

    A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location. To exploit this vulnerability, an…

  • CVE-2024-50929MedDec 10, 2024
    risk 0.40cvss 6.2epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).

  • CVE-2024-22121MedAug 12, 2024
    risk 0.40cvss 6.1epss 0.00

    A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

  • CVE-2024-4768MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.01

    A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

  • CVE-2021-35079MedJun 14, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile