VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 9 of 88
  • CVE-2024-11497HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.00

    An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.

  • CVE-2024-55411HigJan 7, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.

  • CVE-2024-8540HigDec 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.

  • CVE-2024-7612HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

  • CVE-2024-41171HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions < V6.24). Affected devices do not properly enforce access restrictions to scripts that are…

  • CVE-2024-7513HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.02

    CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.

  • CVE-2024-6435HigJul 16, 2024
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data,…

  • CVE-2024-28827HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.

  • CVE-2024-37369HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system.

  • CVE-2024-3668HigJun 8, 2024
    risk 0.57cvss 8.8epss 0.00

    The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible…

  • CVE-2023-49257HigJan 12, 2024
    risk 0.57cvss 8.8epss 0.00

    An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.

  • CVE-2023-46142HigDec 14, 2023
    risk 0.57cvss 8.8epss 0.01

    A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.

  • CVE-2023-46449HigOct 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

  • CVE-2023-4665HigSep 15, 2023
    risk 0.57cvss 8.8epss 0.01

    Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.

  • CVE-2023-40754HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.01

    In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-32992HigMay 16, 2023
    risk 0.57cvss 8.8epss 0.01

    Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.

  • CVE-2023-22294HigApr 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.

  • CVE-2022-44715HigJan 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

  • CVE-2022-40756HigSep 30, 2022
    risk 0.57cvss 8.8epss 0.01

    If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security…

  • CVE-2022-40298HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level…