VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 38 of 88
  • CVE-2023-52715HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-30413HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52116HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

  • CVE-2023-52107HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-42489HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource

  • CVE-2023-34437HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.

  • CVE-2023-42189HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote…

  • CVE-2023-5077HigSep 29, 2023
    risk 0.49cvss 7.6epss 0.00

    The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

  • CVE-2023-4332HigAug 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

  • CVE-2023-39005HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

  • CVE-2023-39003HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

  • CVE-2022-44719HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.

  • CVE-2023-29860HigJun 23, 2023
    risk 0.49cvss 7.5epss 0.01

    An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.

  • CVE-2023-1692HigMay 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-0207HigApr 22, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2022-43946HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file…

  • CVE-2022-25992HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.00

    Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21939HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

  • CVE-2021-37306HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.

  • CVE-2021-37305HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.04

    An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.