VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 64 of 88
  • CVE-2019-19727MedJan 13, 2020
    risk 0.36cvss 5.5epss 0.00

    SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.

  • CVE-2019-19341MedDec 19, 2019
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could…

  • CVE-2019-9464MedDec 6, 2019
    risk 0.36cvss 5.5epss 0.00

    In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could dissolve the trust in the platform's permission system, with no additional…

  • CVE-2013-0326MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    OpenStack nova base images permissions are world readable

  • CVE-2019-5212MedNov 29, 2019
    risk 0.36cvss 5.5epss 0.01

    There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to certain file from certain application. An attacker tricks the user into installing a malicious application then establishing a connect to the attacker through…

  • CVE-2019-3866MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

  • CVE-2018-20908MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).

  • CVE-2019-5222MedJul 17, 2019
    risk 0.36cvss 5.5epss 0.01

    There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit certain system privilege. An attacker tricks the user to install a malicious…

  • CVE-2019-13142MedJul 9, 2019
    risk 0.36cvss 5.5epss 0.00

    The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of…

  • CVE-2018-4324MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.01

    A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. This issue affected versions prior to macOS Mojave 10.14.

  • CVE-2018-4178MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.00

    A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue affected versions prior to macOS High Sierra 10.13.4.

  • CVE-2018-4051MedApr 2, 2019
    risk 0.36cvss 5.5epss 0.00

    An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally create directories and subdirectories on the root file system, as well as change the permissions of existing…

  • CVE-2019-2001MedFeb 28, 2019
    risk 0.36cvss 5.5epss 0.00

    The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-117422211.

  • CVE-2018-9867MedFeb 19, 2019
    risk 0.36cvss 5.5epss 0.00

    In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version…

  • CVE-2019-0111MedFeb 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2019-0108MedFeb 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of information via local access.

  • CVE-2018-3705MedDec 14, 2018
    risk 0.36cvss 5.5epss 0.00

    Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authenticated users to potentially enable a denial of service via local access.

  • CVE-2018-11002MedNov 29, 2018
    risk 0.36cvss 5.5epss 0.01

    Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.

  • CVE-2018-19072MedNov 7, 2018
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/app has 0777 permissions, allowing local users to replace an archive…

  • CVE-2018-11951MedOct 26, 2018
    risk 0.36cvss 5.5epss 0.00

    Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 845, SD 850.