VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 40 of 88
  • CVE-2020-26106HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).

  • CVE-2020-13915HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.02

    Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720,…

  • CVE-2020-3312HigMay 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application…

  • CVE-2019-19218HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.

  • CVE-2020-12120HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.

  • CVE-2019-12441HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue which resulted in a bypass of the protected branches restriction rules. It has Incorrect Access Control.

  • CVE-2019-18856HigNov 11, 2019
    risk 0.49cvss 7.5epss 0.01

    A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.

  • CVE-2007-5743HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.01

    viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

  • CVE-2019-10084HigNov 5, 2019
    risk 0.49cvss 7.5epss 0.01

    In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query…

  • CVE-2019-11528HigOct 10, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.

  • CVE-2019-11270HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.01

    Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator…

  • CVE-2018-20500HigMay 17, 2019
    risk 0.49cvss 7.5epss 0.01

    An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of…

  • CVE-2018-4028HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.01

    An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. The HTTP server could allow an attacker to overwrite the root directory of the server, resulting in a denial of service. An attacker…

  • CVE-2018-19374HigApr 30, 2019
    risk 0.49cvss 7.0epss 0.01

    Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.

  • CVE-2018-15508HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running the Five9 SoftPhone(issue 1 of 2).

  • CVE-2018-19393HigMar 15, 2019
    risk 0.49cvss 7.5epss 0.02

    Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this…

  • CVE-2018-20798HigMar 1, 2019
    risk 0.49cvss 7.5epss 0.01

    The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.

  • CVE-2018-18332HigDec 21, 2018
    risk 0.49cvss 7.5epss 0.01

    A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.

  • CVE-2018-18331HigDec 21, 2018
    risk 0.49cvss 7.5epss 0.01

    A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.

  • CVE-2018-15835HigNov 30, 2018
    risk 0.49cvss 7.5epss 0.02

    Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.