← Back
CWE-732

1,663 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

JSON object

Loading...

CVEs (1,663)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Application Policy Infrastructure Controller
Nov 21, 2024
Aug 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (...Show more
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy for policies outside the tenant boundaries. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete policies created by users associated with a different security domain. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.Show less
1Cisco
8Firepower 4112 Firmware
Firepower 4115Firepower 4125 Firmware+5 more
Nov 21, 2024
Aug 23, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could all...Show more
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the improper handling of specific SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: This vulnerability affects all supported SNMP versions. To exploit this vulnerability through SNMPv2c or earlier, an attacker must know the SNMP community string that is configured on an affected device. To exploit this vulnerability through SNMPv3, the attacker must have valid credentials for an SNMP user who is configured on the affected device.Show less
1Escanav
1Escan Anti Virus
Nov 21, 2024
Aug 16, 2023
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation leads to incorrect execution-assigned perm...Show more
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation leads to incorrect execution-assigned permissions. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237315. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Broadcom
1Raid Controller Web Interface
Nov 4, 2025
Aug 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
1Intel
1Oneapi Math Kernel Library
Nov 21, 2024
Aug 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Opnsense
1Opnsense
Nov 21, 2024
Aug 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
1Opnsense
1Opnsense
Nov 21, 2024
Aug 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which...Show more
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.Show less
1Opnsense
1Opnsense
Nov 21, 2024
Aug 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
1Siemens
1Sicam Toolbox Ii
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges t...Show more
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges to replace DLLs and conduct a privilege escalation.Show less
2Fedoraproject
Rust Lang
2Cargo
Fedora
Nov 21, 2024
Aug 4, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like sy...Show more
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.Show less
1Jeesite
1Jeesite
Nov 21, 2024
Aug 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.
1Cisco
12Broadworks Application Delivery Platform
Broadworks Application ServerBroadworks Database Server+9 more
Nov 21, 2024
Aug 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is d...Show more
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.Show less
1Abb
1Zenon
Nov 21, 2024
Jul 24, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exp...Show more
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404. Show less
1Checkpoint
1Endpoint Security
Nov 21, 2024
Jul 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
1Sap
1S4core
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on co...Show more
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable.Show less
1Sap
1Sql Anywhere
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into th...Show more
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an attacker to perform a Denial of Service. Further, an attacker might be able to modify sensitive data in shared memory objects.This issue only affects SAP SQL Anywhere on Windows. Other platforms are not impacted.Show less
1Ucopia
1Wireless Appliance Firmware
Nov 21, 2024
Jun 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
1Veritas
1Netbackup Appliance
Nov 21, 2024
Jun 29, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
1Stormshield
1Endpoint Security
Nov 21, 2024
Jun 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read d...Show more
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.Show less
1Stormshield
1Endpoint Security
Nov 21, 2024
Jun 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.