CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 11 of 34
- CVE-2021-0093MEDIUMCVSS 4.4EG 4.42022-02-09
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
- CVE-2021-0100HIGHCVSS 7.8EG 7.82021-06-09
Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2020, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0105HIGHCVSS 7.3EG 7.32021-06-09
Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclosure and denial of service via adjacent access.
- CVE-2021-0106HIGHCVSS 7.8EG 7.82021-06-09
Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0143HIGHCVSS 7.8EG 7.82021-06-17
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0235HIGHCVSS 7.3EG 7.32021-04-22
On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Juniper Networks Junos OS, due to incorrect permission scheme assigned to tenant system administrators, a tenant system admi…
- CVE-2021-0246HIGHCVSS 7.3EG 7.32021-04-22
On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services on Juniper Networks Junos OS, due to incorrect default permissions assigned to tenant system administrators a tenant system administrator m…
- CVE-2021-0380HIGHCVSS 7.8EG 7.82021-03-10
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission check. This could lead to local escalation of privilege during the onboarding flow with n…
- CVE-2021-0381MEDIUMCVSS 5.5EG 5.52021-03-10
In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is no…
- CVE-2021-0382MEDIUMCVSS 5.5EG 5.52021-03-10
In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges needed. User interacti…
- CVE-2021-0389HIGHCVSS 7.8EG 7.82021-03-10
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pr…
- CVE-2021-0428MEDIUMCVSS 5.5EG 5.52021-04-13
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interacti…
- CVE-2021-0441HIGHCVSS 7.3EG 7.32021-07-14
In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation…
- CVE-2021-0486HIGHCVSS 7.8EG 7.82021-07-14
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction …
- CVE-2021-0588MEDIUMCVSS 5.5EG 5.52021-07-14
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…
- CVE-2021-0590MEDIUMCVSS 4.4EG 4.42021-07-14
In sendNetworkConditionsBroadcast of NetworkMonitor.java, there is a possible way for a privileged app to receive WiFi BSSID and SSID without location permissions due to a missing permission check. This could lead to local information disc…
- CVE-2021-0603HIGHCVSS 7.8EG 7.82021-07-14
In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. …
- CVE-2021-0654MEDIUMCVSS 5.5EG 5.52021-07-14
In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges needed. User inter…
- CVE-2021-0672MEDIUMCVSS 5.5EG 5.52021-11-18
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P…
- CVE-2021-0706MEDIUMCVSS 5.5EG 5.52021-10-22
In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User int…
- CVE-2021-0735MEDIUMCVSS 5.5EG 5.52022-08-11
In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional exec…
- CVE-2021-0904MEDIUMCVSS 6.7EG 6.72021-12-15
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
- CVE-2021-0979MEDIUMCVSS 5.5EG 5.52021-12-15
In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local informat…
- CVE-2021-1000HIGHCVSS 7.8EG 7.82022-03-30
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2021-1033HIGHCVSS 7.8EG 7.82022-03-30
In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2021-1056HIGHCVSS 7.1EG 7.12021-01-08
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which ma…
- CVE-2021-1831MEDIUMCVSS 5.5EG 5.52021-09-08
The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to access restricted files.
- CVE-2021-1832MEDIUMCVSS 5.5EG 5.52021-09-08
Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. The issue was addressed with improved permissions logi…
- CVE-2021-20001CRITICALCVSS 9.8EG 9.82022-02-11
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
- CVE-2021-20037HIGHCVSS 7.8EG 7.82021-09-21
SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This vulnerability impa…
- CVE-2021-20269MEDIUMCVSS 5.5EG 6.22022-03-10
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability i…
- CVE-2021-20490MEDIUMCVSS 5.5EG 5.52021-06-29
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.
- CVE-2021-20532HIGHCVSS 7.8EG 7.82021-04-26
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.
- CVE-2021-20653MEDIUMCVSS 5.3EG 5.32021-02-17
Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote attackers to bypass access restriction and to obtain unauthorized historical data without ac…
- CVE-2021-21436LOWCVSS 3.5EG 3.52021-02-08
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
- CVE-2021-21438LOWCVSS 3.5EG 3.52021-03-22
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.
- CVE-2021-21732HIGHCVSS 7.5EG 7.52021-05-19
A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper permission settings, third-party applications can read some files in the proc file system without authorization. Attackers could exploit this vulne…
- CVE-2021-21736HIGHCVSS 7.2EG 7.22021-06-10
A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camer…
- CVE-2021-21737HIGHCVSS 7.5EG 7.52021-06-24
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system custo…
- CVE-2021-21910HIGHCVSS 7.8EG 7.82021-12-22
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM au…
- CVE-2021-21911HIGHCVSS 7.8EG 7.82021-12-22
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM au…
- CVE-2021-21912HIGHCVSS 7.8EG 7.82021-12-22
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM au…
- CVE-2021-21957HIGHCVSS 7.3EG 8.82021-12-08
A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious …
- CVE-2021-22295MEDIUMCVSS 5.5EG 5.52021-08-06
A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.
- CVE-2021-22311HIGHCVSS 7.2EG 7.22021-03-22
There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations wi…
- CVE-2021-22346MEDIUMCVSS 5.3EG 5.32021-06-30
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to the disclosure of user habits.
- CVE-2021-22368HIGHCVSS 7.5EG 7.52021-06-30
There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.
- CVE-2021-22371HIGHCVSS 7.5EG 7.52021-06-30
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-22376HIGHCVSS 8.4EG 8.42021-06-30
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
- CVE-2021-22475MEDIUMCVSS 5.3EG 5.32021-10-28
There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →