CWE-269
2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,777)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phoenixcontact 1Plcnext Firmware Nov 21, 2024 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges. |
3Debian FedoraprojectXen3Debian Linux FedoraXenNov 21, 2024 Dec 15, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain c...Show more |
1Citrix 3Virtual Apps And Desktops XenappXendesktopNov 21, 2024 Dec 14, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hot...Show more |
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files. |
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks |
1Cisco 2Jabber Jabber For Mobile PlatformsNov 21, 2024 Dec 11, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Cisco 2Jabber Jabber For Mobile PlatformsNov 21, 2024 Dec 11, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Cisco 2Jabber Jabber For Mobile PlatformsNov 21, 2024 Dec 11, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019May 18, 2026 Dec 10, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
2Redhat Samba3Enterprise Linux SambaStorageNov 21, 2024 Dec 3, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the att...Show more |
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction lin...Show more |
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the ad...Show more |
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges. |
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have acc...Show more |
1Schneider Electric 1Operator Terminal Expert Runtime Nov 21, 2024 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver in...Show more |
1Endress 4Orsg35 Firmware Orsg45 FirmwareRsg35 Firmware+1 moreNov 21, 2024 Nov 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based acce...Show more |
1Cisco 2Expressway Telepresence Video Communication ServerNov 21, 2024 Nov 18, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restri...Show more |
1Cisco 1Iot Field Network Director Nov 21, 2024 Nov 18, 2020 N/A· v4 4.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system...Show more |
1Cisco 1Iot Field Network Director Nov 21, 2024 Nov 18, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected...Show more |
1Cisco 1Iot Field Network Director Nov 21, 2024 Nov 18, 2020 N/A· v4 8.7 HIGH· v3 5.5 MEDIUM· v2 A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is...Show more |