VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,787)

page 83 of 90
  • CVE-2019-19086MedJan 3, 2020
    risk 0.21cvss 4.3epss 0.01

    Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).

  • CVE-2012-6655LowNov 27, 2019
    risk 0.21cvss 3.3epss 0.00

    An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

  • CVE-2019-13679LowNov 25, 2019
    risk 0.21cvss 3.3epss 0.01

    Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.

  • CVE-2019-15340LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006)…

  • CVE-2019-15339LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…

  • CVE-2019-15338LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app…

  • CVE-2019-15337LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device…

  • CVE-2019-15336LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app…

  • CVE-2019-15335LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device…

  • CVE-2019-15334LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app…

  • CVE-2019-15333LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…

  • CVE-2019-5642LowNov 6, 2019
    risk 0.21cvss 3.3epss 0.00

    Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is…

  • CVE-2016-4983LowNov 5, 2019
    risk 0.21cvss 3.3epss 0.00

    A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

  • CVE-2019-11806LowAug 20, 2019
    risk 0.21cvss 3.3epss 0.00

    OX App Suite 7.10.1 and earlier has Insecure Permissions.

  • CVE-2018-20936LowAug 1, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).

  • CVE-2019-14395LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).

  • CVE-2018-12209LowMar 14, 2019
    risk 0.21cvss 3.3epss 0.00

    Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an…

  • CVE-2019-7729LowFeb 22, 2019
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving video clips or still images that have been cached for clip sharing. (The Bosch Smart Home App is not…

  • CVE-2012-0433LowJun 8, 2018
    risk 0.21cvss 3.3epss 0.00

    The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.

  • CVE-2017-1699LowJan 4, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.