← Back
CWE-732

1,744 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

JSON object

Loading...

CVEs (1,744)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Openstack
Nov 21, 2024
Oct 31, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access...Show more
A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access unauthorized system information.Show less
1Asrock
4A Tuning
F StreamRestart To Uefi+1 more
Nov 21, 2024
Oct 30, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/...Show more
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.Show less
1Asrock
4A Tuning
F StreamRestart To Uefi+1 more
Nov 21, 2024
Oct 30, 2018
N/A· v4
7.1 HIGH· v3
7.2 HIGH· v2
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitr...Show more
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.Show less
1Asrock
4A Tuning
F StreamRestart To Uefi+1 more
Nov 21, 2024
Oct 30, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR reg...Show more
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. This could be leveraged in a number of ways to ultimately run code with elevated privileges.Show less
1Qualcomm
2Sd 845 Firmware
Sd 850 Firmware
Nov 21, 2024
Oct 26, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 845, SD 850.
1Debian
1Crossroads
Nov 21, 2024
Oct 26, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process...Show more
Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of this subdirectory to include a Trojan horse xr.Show less
1Apache
1Impala
Nov 21, 2024
Oct 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the...Show more
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.Show less
1Wifiranger
1Wifiranger Firmware
Nov 21, 2024
Oct 23, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in t...Show more
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.Show less
1Splunk
1Splunk
Nov 21, 2024
Oct 19, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/s...Show more
Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/splunk-launch.conf and insert Trojan horse programs into $SPLUNK_HOME/bin, because the non-root setup instructions state that chown should be run across all of $SPLUNK_HOME to give non-root access.Show less
1Emc
1Secure Remote Services
Nov 21, 2024
Oct 18, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-readable permissions that could allow an...Show more
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-readable permissions that could allow an authenticated malicious user to utilize the file contents to potentially elevate their privileges.Show less
1Huawei
1Anne Al00 Firmware
Jun 17, 2026
Oct 17, 2018
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
Anne-AL00 Huawei phones with versions earlier than 8.0.0.151(C00) have an information leak vulnerability. Due to improper permission settings for specific commands, attackers who can connect to a mobile phone via the USB...Show more
Anne-AL00 Huawei phones with versions earlier than 8.0.0.151(C00) have an information leak vulnerability. Due to improper permission settings for specific commands, attackers who can connect to a mobile phone via the USB interface may exploit this vulnerability to obtain specific device information of the mobile phone.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Oct 16, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Oct 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, which could allow user account compromise an...Show more
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, which could allow user account compromise and may allow for remote code execution.Show less
1Ibm
1Spectrum Lsf
Nov 21, 2024
Oct 11, 2018
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.
1Intel
14Compute Module Hns2600bp Firmware
Compute Module Hns2600bpr FirmwareServer Board S2600bp Firmware+11 more
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.6 HIGH· v3
7.2 HIGH· v2
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary cod...Show more
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.Show less
1Intel
3Client Nvme
Datacenter NvmeRapid Storage Technology
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticated user to potentially escalate privilege via local access.
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Jun 17, 2026
Oct 10, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Win...Show more
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.Show less
1Seqrite
1End Point Security
Nov 21, 2024
Oct 8, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 8, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 148511.
1Dell
2Emc Unity Operating Environment
Emc Unityvsa Operating Environment
Nov 21, 2024
Oct 5, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vuln...Show more
Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability to alter multiple library files in service tools that might result in arbitrary code execution with elevated privileges. No user file systems are directly affected by this vulnerability.Show less