CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 14 of 34
- CVE-2021-39734HIGHCVSS 7.8EG 7.82022-03-16
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges…
- CVE-2021-39747MEDIUMCVSS 5.5EG 5.52022-03-30
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is n…
- CVE-2021-39748MEDIUMCVSS 5.5EG 5.52022-03-30
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is n…
- CVE-2021-39769MEDIUMCVSS 5.5EG 5.52022-03-30
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges neede…
- CVE-2021-39770MEDIUMCVSS 5.5EG 5.52022-03-30
In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for …
- CVE-2021-39779MEDIUMCVSS 5.5EG 5.52022-03-30
In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2021-39780HIGHCVSS 7.8EG 7.82022-03-30
In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User …
- CVE-2021-39794HIGHCVSS 7.8EG 7.82022-04-12
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no addition…
- CVE-2021-3981LOWCVSS 3.3EG 3.32022-03-10
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those use…
- CVE-2021-39886LOWCVSS 2.6EG 2.62021-10-05
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
- CVE-2021-39967HIGHCVSS 7.5EG 7.52022-01-03
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-40004HIGHCVSS 7.5EG 7.52022-01-10
The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-40049HIGHCVSS 7.5EG 7.52022-03-10
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
- CVE-2021-40053CRITICALCVSS 9.1EG 9.12022-03-10
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
- CVE-2021-40059MEDIUMCVSS 6.5EG 6.52022-03-10
There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2021-40123MEDIUMCVSS 4.3EG 4.32021-10-21
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerab…
- CVE-2021-40388HIGHCVSS 8.8EG 8.82022-01-28
A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger thi…
- CVE-2021-40389HIGHCVSS 8.8EG 8.82022-01-28
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malic…
- CVE-2021-40396HIGHCVSS 8.8EG 8.82022-01-28
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious…
- CVE-2021-40397HIGHCVSS 7.8EG 7.82022-01-28
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malici…
- CVE-2021-40413HIGHCVSS 7.1EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of…
- CVE-2021-40414HIGHCVSS 7.1EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sen…
- CVE-2021-40415MEDIUMCVSS 6.5EG 6.52022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will …
- CVE-2021-40416HIGHCVSS 8.8EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any lo…
- CVE-2021-40904HIGHCVSS 8.8EG 8.82022-03-25
The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successfu…
- CVE-2021-41166MEDIUMCVSS 4.3EG 4.32022-01-26
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise req…
- CVE-2021-41614HIGHCVSS 7.8EG 7.82023-04-18
An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter Register (EPCR) are not implemented correctly. User programs from an unauthorized privilege…
- CVE-2021-41635HIGHCVSS 8.8EG 8.82022-06-24
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
- CVE-2021-41637HIGHCVSS 7.1EG 7.12022-06-24
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
- CVE-2021-41652HIGHCVSS 7.5EG 7.52022-03-01
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
- CVE-2021-42011HIGHCVSS 7.8EG 7.82021-10-21
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain t…
- CVE-2021-42055MEDIUMCVSS 6.8EG 6.82021-10-18
ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.
- CVE-2021-42098HIGHCVSS 8.8EG 8.82021-10-18
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.
- CVE-2021-42711HIGHCVSS 7.8EG 7.82021-12-01
Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation.
- CVE-2021-4297CRITICALCVSS 5.5EG 9.82023-01-01
A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the file application/controllers/Restapi.php. The manipulation of the argument sourcefilename …
- CVE-2021-43199MEDIUMCVSS 5.3EG 5.32021-11-09
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
- CVE-2021-43325HIGHCVSS 7.8EG 7.82021-12-15
Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.
- CVE-2021-43326HIGHCVSS 7.8EG 7.82021-12-15
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
- CVE-2021-43860HIGHCVSS 8.2EG 8.22022-01-12
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions…
- CVE-2021-43986HIGHCVSS 6.0EG 7.82022-04-20
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.
- CVE-2021-44140CRITICALCVSS 9.1EG 9.12021-11-24
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance…
- CVE-2021-44215MEDIUMCVSS 5.5EG 5.52022-03-10
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
- CVE-2021-44216MEDIUMCVSS 5.5EG 5.52022-03-10
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
- CVE-2021-44470MEDIUMCVSS 5.5EG 5.52022-08-18
Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2021-44751MEDIUMCVSS 4.3EG 5.32022-03-25
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to sen…
- CVE-2021-44833CRITICALCVSS 9.8EG 9.82021-12-12
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
- CVE-2021-44858HIGHCVSS 7.5EG 7.52021-12-20
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has a…
- CVE-2021-44905HIGHCVSS 8.2EG 8.22022-03-25
Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name.
- CVE-2021-45003CRITICALCVSS 9.8EG 9.82022-01-10
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.
- CVE-2021-45083HIGHCVSS 7.1EG 7.12022-02-20
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.dig…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →