← Back
CWE-552

506 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectOpensuse+1 more
5Debian Linux
Enterprise LinuxFedora+2 more
Jun 17, 2026
Jan 15, 2019
N/A· v4
5.2 MEDIUM· v3
2.7 LOW· v2
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that res...Show more
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.Show less
1Lg
18Lnb5110 Firmware
Lnb5320 FirmwareLnb5320r Firmware+15 more
Nov 21, 2024
Sep 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without aut...Show more
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.Show less
2Openstack
Redhat
2Heat
Openstack
Nov 21, 2024
Jul 27, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this fl...Show more
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.Show less
1Redhat
1Openstack
Nov 21, 2024
Jul 27, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive informatio...Show more
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.Show less
1Redhat
2Certification
Enterprise Linux
Nov 21, 2024
Jul 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.
2Canonical
Mozilla
2Firefox
Ubuntu Linux
Nov 21, 2024
Jun 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development...Show more
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.Show less
2Clusterlabs
Redhat
2Enterprise Linux
Pacemaker Command Line Interface
Nov 21, 2024
Apr 12, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_fil...Show more
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could create or overwrite arbitrary files with arbitrary data outside of the /etc/booth directory, in the context of the pcsd process.Show less
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Mar 23, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
1Cisco
1Elastic Services Controller
Nov 21, 2024
Jan 18, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insuffic...Show more
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insufficient security restrictions. An attacker could exploit this vulnerability by accessing unauthorized information within the ConfD directory and file structure. Successful exploitation could allow the attacker to view sensitive information. Cisco Bug IDs: CSCvg00221.Show less
2Heketi Project
Redhat
2Enterprise Linux
Heketi
May 13, 2026
Dec 18, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
1Synology
1Photo Station
May 13, 2026
Dec 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
2Debian
Roundcube
2Debian Linux
Webmail
Apr 21, 2026
Nov 9, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017...Show more
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.Show less
1Apple
1Itunes
May 13, 2026
Oct 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.
1Microsoft
2Windows 10
Windows Server 2016
May 13, 2026
Oct 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
1Intelbras
1Wrn 150 Firmware
May 13, 2026
Sep 30, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.
1Inpsyde
1Backwpup
May 13, 2026
Sep 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
1Zte
4Zxr10 160 Firmware
Zxr10 1800 2s FirmwareZxr10 2800 4 Firmware+1 more
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator acco...Show more
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.Show less
1Cisco
1Asr 5000 Software
May 13, 2026
Aug 17, 2017
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerabilit...Show more
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerability is due to the inclusion of sensitive system files within specific FTP subdirectories. An attacker could exploit this vulnerability by overwriting sensitive configuration files through FTP. An exploit could allow the attacker to overwrite configuration files on an affected system. Cisco Bug IDs: CSCvd47739. Known Affected Releases: 21.0.v0.65839.Show less
1Fortinet
1Fortiweb
May 13, 2026
Aug 10, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
1Inversepath
1Tenshi
May 13, 2026
Jul 30, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification b...Show more
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat /pathname/tenshi.pid`" command.Show less