CWE-269
2,753 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,753)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can impersonate a user with web restore permission. When requesting the toke...Show more |
1Llnl 1Model Specific Registers Safe Nov 21, 2024 Jul 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: A...Show more |
The Windows versions of Snapview Mikogo, versions before 5.10.2 are affected by insecure implementations which allow local attackers to escalate privileges. |
Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service. |
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain root access by conne...Show more |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsNov 21, 2024 Jun 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malic...Show more |
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882. |
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019May 20, 2025 Jun 12, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a...Show more |
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however...Show more |
1Enttec 4Datagate Mk2 Firmware E Streamer Mk2 FirmwarePixelator Firmware+1 moreNov 21, 2024 Jun 7, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropria...Show more |
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227. |
1Ibm 10Control Desk Maximo Asset ManagementMaximo For Aviation+7 moreNov 21, 2024 Jun 6, 2019 N/A· v4 2.1 LOW· v3 2.1 LOW· v2 IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311. |
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service. |
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the application...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permiss...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 8.0 HIGH· v3 4.9 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissio...Show more |
1Bosch 1Smart Home Controller Firmware Nov 21, 2024 May 29, 2019 N/A· v4 8.0 HIGH· v3 5.4 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In...Show more |
1Ca 2Risk Authentication Strong AuthenticationNov 21, 2024 May 28, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows...Show more |
1Microsoft 1Azure Active Directory Connect Nov 21, 2024 May 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privil...Show more |