VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 12 of 88
  • CVE-2019-10710HigApr 23, 2019
    risk 0.57cvss 8.8epss 0.01

    Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE,…

  • CVE-2018-17305HigApr 11, 2019
    risk 0.57cvss 8.8epss 0.01

    UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.

  • CVE-2018-5413HigJan 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.

  • CVE-2018-13321HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.01

    Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "method" parameter.

  • CVE-2018-6057HigNov 14, 2018
    risk 0.57cvss 8.8epss 0.01

    Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.

  • CVE-2018-17873HigOct 23, 2018
    risk 0.57cvss 8.8epss 0.02

    An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.

  • CVE-2018-17892HigOct 12, 2018
    risk 0.57cvss 8.8epss 0.03

    NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, which could allow user account compromise and may allow for remote code execution.

  • CVE-2018-17872HigOct 4, 2018
    risk 0.57cvss 8.8epss 0.02

    Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.

  • CVE-2018-17037HigSep 14, 2018
    risk 0.57cvss 8.8epss 0.01

    user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.

  • CVE-2018-13411HigSep 12, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.

  • CVE-2018-16715HigSep 8, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged user accounts. This allows unauthorized replacement of service program…

  • CVE-2018-1000649HigAug 20, 2018
    risk 0.57cvss 8.8epss 0.03

    LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be…

  • CVE-2018-5490HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running…

  • CVE-2018-1000209HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.01

    Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can result in Unprivileged users may execute code in context of Sensu service account. This attack appear to be exploitable via…

  • CVE-2018-14043CriJul 13, 2018
    risk 0.57cvss 9.8epss 0.02

    mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operation, related to fs/m_fs.c and fs/m_fs_path.c. An attacker…

  • CVE-2018-11116HigJun 19, 2018
    risk 0.57cvss 8.8epss 0.02

    OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the…

  • CVE-2018-12027HigJun 17, 2018
    risk 0.57cvss 8.8epss 0.01

    An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent…

  • CVE-2018-4220HigJun 8, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu" component. It allows attackers to execute arbitrary code in a privileged context because write and execute permissions are…

  • CVE-2018-11194HigJun 2, 2018
    risk 0.57cvss 8.8epss 0.03

    Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6).

  • CVE-2018-11193HigJun 2, 2018
    risk 0.57cvss 8.8epss 0.03

    Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6).