VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,754)

page 4 of 88
  • CVE-2020-12838CriSep 24, 2020
    risk 0.64cvss 9.8epss 0.02

    ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.

  • CVE-2020-24355CriSep 2, 2020
    risk 0.64cvss 9.8epss 0.02

    Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is…

  • CVE-2020-9671CriJul 17, 2020
    risk 0.64cvss 9.8epss 0.04

    Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2020-9024CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.

  • CVE-2012-2087CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.03

    ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

  • CVE-2019-8256CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.04

    ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2019-8071CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.03

    Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2019-11526CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

  • CVE-2019-7958CriAug 16, 2019
    risk 0.64cvss 9.8epss 0.04

    Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2018-20871CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).

  • CVE-2019-1010101CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.03

    Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377,…

  • CVE-2019-1010009CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.03

    DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT API. The attack vector is: Any Accessible Server.

  • CVE-2018-10171CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyzer.AdwareAnalyzerPrivilegedHelper` component. The AdwareAnalzyerPrivilegedHelper tool implements an XPC service that allows an unprivileged application to…

  • CVE-2019-12042CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.04

    Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which…

  • CVE-2017-9626CriMar 27, 2019
    risk 0.64cvss 9.8epss 0.02

    Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.

  • CVE-2018-15509CriMar 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).

  • CVE-2018-10612CriJan 29, 2019
    risk 0.64cvss 9.8epss 0.01

    In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.

  • CVE-2018-14703CriDec 3, 2018
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.

  • CVE-2018-11792CriOct 24, 2018
    risk 0.64cvss 9.8epss 0.02

    In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically…

  • CVE-2018-11240CriSep 21, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in…