VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,754)

page 2 of 88
  • CVE-2025-8042CriAug 19, 2025
    risk 0.64cvss 9.8epss 0.00

    Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.

  • CVE-2025-46093CriAug 4, 2025
    risk 0.64cvss 9.9epss 0.01

    LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

  • CVE-2025-45150CriAug 1, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.

  • CVE-2025-43243CriJul 30, 2025
    risk 0.64cvss 9.8epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.

  • CVE-2017-20198CriJul 23, 2025
    risk 0.64cvss epss 0.01

    The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount configurations, attackers can deploy a container that mounts the host's root filesystem (/) with read/write privileges. When using a…

  • CVE-2025-25373CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.00

    The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

  • CVE-2024-53351CriMar 21, 2025
    risk 0.64cvss 9.8epss 0.00

    Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.

  • CVE-2024-57520CriFeb 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka…

  • CVE-2025-0066CriJan 14, 2025
    risk 0.64cvss 9.9epss 0.01

    Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an…

  • CVE-2024-10018CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.

  • CVE-2024-24117CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

  • CVE-2024-6360CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0…

  • CVE-2024-9142CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.00

    External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls. This issue affects e-Belediye: before 2.0.642.

  • CVE-2024-8039CriSep 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

  • CVE-2024-5618CriJul 18, 2024
    risk 0.64cvss 9.9epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: before 2024.05.1.

  • CVE-2024-5163CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.

  • CVE-2024-33435CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.php backend function

  • CVE-2020-36770CriJan 15, 2024
    risk 0.64cvss 9.8epss 0.00

    pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.

  • CVE-2023-46141CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

  • CVE-2023-0757CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.