CWE-732
Incorrect Permission Assignment for Critical Resource
Description
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642
CVEs mapped to this weakness (1,754)
page 4 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12838 | Cri | 0.64 | 9.8 | 0.02 | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php. | ||
| CVE-2020-24355 | Cri | 0.64 | 9.8 | 0.02 | Sep 2, 2020 | Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is… | ||
| CVE-2020-9671 | Cri | 0.64 | 9.8 | 0.04 | Jul 17, 2020 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | ||
| CVE-2020-9024 | Cri | 0.64 | 9.8 | 0.02 | Feb 17, 2020 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts. | ||
| CVE-2012-2087 | Cri | 0.64 | 9.8 | 0.03 | Jan 23, 2020 | ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface. | ||
| CVE-2019-8256 | Cri | 0.64 | 9.8 | 0.04 | Dec 19, 2019 | ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation. | ||
| CVE-2019-8071 | Cri | 0.64 | 9.8 | 0.03 | Oct 17, 2019 | Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | ||
| CVE-2019-11526 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations. | ||
| CVE-2019-7958 | Cri | 0.64 | 9.8 | 0.04 | Aug 16, 2019 | Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lead to privilege escalation. | ||
| CVE-2018-20871 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2019 | In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890). | ||
| CVE-2019-1010101 | Cri | 0.64 | 9.8 | 0.03 | Jul 19, 2019 | Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377,… | ||
| CVE-2019-1010009 | Cri | 0.64 | 9.8 | 0.03 | Jul 15, 2019 | DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT API. The attack vector is: Any Accessible Server. | ||
| CVE-2018-10171 | Cri | 0.64 | 9.8 | 0.02 | Jun 5, 2019 | Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyzer.AdwareAnalyzerPrivilegedHelper` component. The AdwareAnalzyerPrivilegedHelper tool implements an XPC service that allows an unprivileged application to… | ||
| CVE-2019-12042 | Cri | 0.64 | 9.8 | 0.04 | May 23, 2019 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which… | ||
| CVE-2017-9626 | Cri | 0.64 | 9.8 | 0.02 | Mar 27, 2019 | Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication. | ||
| CVE-2018-15509 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2019 | Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2). | ||
| CVE-2018-10612 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2019 | In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials. | ||
| CVE-2018-14703 | Cri | 0.64 | 9.8 | 0.01 | Dec 3, 2018 | Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password. | ||
| CVE-2018-11792 | Cri | 0.64 | 9.8 | 0.02 | Oct 24, 2018 | In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically… | ||
| CVE-2018-11240 | Cri | 0.64 | 9.8 | 0.02 | Sep 21, 2018 | An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in… |
- risk 0.64cvss 9.8epss 0.02
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
- risk 0.64cvss 9.8epss 0.02
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is…
- risk 0.64cvss 9.8epss 0.04
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
- risk 0.64cvss 9.8epss 0.02
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.
- risk 0.64cvss 9.8epss 0.03
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
- risk 0.64cvss 9.8epss 0.04
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
- risk 0.64cvss 9.8epss 0.03
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.
- risk 0.64cvss 9.8epss 0.04
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lead to privilege escalation.
- risk 0.64cvss 9.8epss 0.02
In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).
- risk 0.64cvss 9.8epss 0.03
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377,…
- risk 0.64cvss 9.8epss 0.03
DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT API. The attack vector is: Any Accessible Server.
- risk 0.64cvss 9.8epss 0.02
Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyzer.AdwareAnalyzerPrivilegedHelper` component. The AdwareAnalzyerPrivilegedHelper tool implements an XPC service that allows an unprivileged application to…
- risk 0.64cvss 9.8epss 0.04
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which…
- risk 0.64cvss 9.8epss 0.02
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.
- risk 0.64cvss 9.8epss 0.02
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
- risk 0.64cvss 9.8epss 0.01
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.
- risk 0.64cvss 9.8epss 0.02
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in…