← Back
CWE-269

2,777 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (2,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phoenixcontact
1Plcnext Firmware
Nov 21, 2024
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
Nov 21, 2024
Dec 15, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain c...Show more
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/<domid> are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.Show less
1Citrix
3Virtual Apps And Desktops
XenappXendesktop
Nov 21, 2024
Dec 14, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hot...Show more
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.Show less
1Citrix
1Gateway Plug In
Nov 21, 2024
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.
1Citrix
1Gateway Plug In
Nov 21, 2024
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks
1Cisco
2Jabber
Jabber For Mobile Platforms
Nov 21, 2024
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Jabber
Jabber For Mobile Platforms
Nov 21, 2024
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Jabber
Jabber For Mobile Platforms
Nov 21, 2024
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
May 18, 2026
Dec 10, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
2Redhat
Samba
3Enterprise Linux
SambaStorage
Nov 21, 2024
Dec 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the att...Show more
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.Show less
1Mcafee
1Total Protection
Nov 21, 2024
Dec 1, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction lin...Show more
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link. This exploits a lack of protection through a timing issue and is only exploitable in a small time window.Show less
1Huawei
1Fusioncompute
Nov 21, 2024
Dec 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the ad...Show more
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.Show less
1Lenovo
1Pcmanager
Nov 21, 2024
Nov 30, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
1Octobercms
1October
Nov 21, 2024
Nov 23, 2020
N/A· v4
4.2 MEDIUM· v3
4.6 MEDIUM· v2
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have acc...Show more
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have access to create & manage users where they can choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access. Issue has been patched in Build 470 (v1.0.470) & v1.1.1.Show less
1Schneider Electric
1Operator Terminal Expert Runtime
Nov 21, 2024
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver in...Show more
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.Show less
1Endress
4Orsg35 Firmware
Orsg45 FirmwareRsg35 Firmware+1 more
Nov 21, 2024
Nov 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based acce...Show more
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.Show less
1Cisco
2Expressway
Telepresence Video Communication Server
Nov 21, 2024
Nov 18, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restri...Show more
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper validation of specific connection information by the TURN server within the affected software. An attacker could exploit this issue by sending specially crafted network traffic to the affected software. A successful exploit could allow the attacker to send traffic through the affected software to destinations beyond the application, possibly allowing the attacker to gain unauthorized network access.Show less
1Cisco
1Iot Field Network Director
Nov 21, 2024
Nov 18, 2020
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system...Show more
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper domain access control. An attacker could exploit this vulnerability by manipulating JSON payloads to target different domains on an affected system. A successful exploit could allow the attacker to manage user information for users in different domains on an affected system.Show less
1Cisco
1Iot Field Network Director
Nov 21, 2024
Nov 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected...Show more
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to improper access control. An attacker could exploit this vulnerability by sending an API request that alters the domain for a requested user list on an affected system. A successful exploit could allow the attacker to view lists of users from different domains on the affected system.Show less
1Cisco
1Iot Field Network Director
Nov 21, 2024
Nov 18, 2020
N/A· v4
8.7 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is...Show more
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by sending SOAP API requests to affected devices for devices that are outside their authorized domain. A successful exploit could allow the attacker to access and modify information on devices that belong to a different domain.Show less