CWE-732
Incorrect Permission Assignment for Critical Resource
Description
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642
CVEs mapped to this weakness (1,752)
page 38 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52715 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2024 | The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-30413 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2024 | Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52116 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device. | ||
| CVE-2023-52107 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-42489 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource | ||
| CVE-2023-34437 | Hig | 0.49 | 7.5 | 0.00 | Oct 19, 2023 | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device. | ||
| CVE-2023-42189 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2023 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote… | ||
| CVE-2023-5077 | Hig | 0.49 | 7.6 | 0.00 | Sep 29, 2023 | The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0. | ||
| CVE-2023-4332 | Hig | 0.49 | 7.5 | 0.01 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file | ||
| CVE-2023-39005 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2023 | Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. | ||
| CVE-2023-39003 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2023 | OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp. | ||
| CVE-2022-44719 | Hig | 0.49 | 7.5 | 0.01 | Jun 29, 2023 | An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions. | ||
| CVE-2023-29860 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2023 | An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method. | ||
| CVE-2023-1692 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2023 | The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-0207 | Hig | 0.49 | 7.5 | 0.00 | Apr 22, 2023 | NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service. | ||
| CVE-2022-43946 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2023 | Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file… | ||
| CVE-2022-25992 | Hig | 0.49 | 7.5 | 0.00 | Feb 16, 2023 | Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2022-21939 | Hig | 0.49 | 7.5 | 0.01 | Feb 9, 2023 | Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie. | ||
| CVE-2021-37306 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin. | ||
| CVE-2021-37305 | Hig | 0.49 | 7.5 | 0.04 | Feb 3, 2023 | An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin. |
- risk 0.49cvss 7.5epss 0.00
The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
- risk 0.49cvss 7.5epss 0.00
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
- risk 0.49cvss 7.5epss 0.01
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote…
- risk 0.49cvss 7.6epss 0.00
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.
- risk 0.49cvss 7.5epss 0.01
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
- risk 0.49cvss 7.5epss 0.01
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
- risk 0.49cvss 7.5epss 0.01
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
- risk 0.49cvss 7.5epss 0.01
An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.
- risk 0.49cvss 7.5epss 0.00
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.
- risk 0.49cvss 7.5epss 0.01
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file…
- risk 0.49cvss 7.5epss 0.00
Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.01
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
- risk 0.49cvss 7.5epss 0.01
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
- risk 0.49cvss 7.5epss 0.04
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.