CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 18 of 34
- CVE-2022-33912HIGHCVSS 7.8EG 7.82022-06-17
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer sc…
- CVE-2022-33922HIGHCVSS 7.0EG 7.82022-10-12
Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security c…
- CVE-2022-33963MEDIUMCVSS 6.7EG 6.72023-05-10
Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-33996HIGHCVSS 8.8EG 8.82022-07-07
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
- CVE-2022-34043HIGHCVSS 7.3EG 7.32022-06-29
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.
- CVE-2022-3430MEDIUMCVSS 6.7EG 6.72023-01-23
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- CVE-2022-3431MEDIUMCVSS 6.7EG 6.72023-10-09
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying …
- CVE-2022-3432MEDIUMCVSS 6.7EG 6.72023-01-26
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variab…
- CVE-2022-3466MEDIUMCVSS 4.8EG 4.82023-09-15
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022…
- CVE-2022-34737CRITICALCVSS 9.1EG 9.12022-07-12
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
- CVE-2022-34824CRITICALCVSS 9.8EG 9.82022-11-08
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for …
- CVE-2022-36367MEDIUMCVSS 4.4EG 4.42022-11-11
Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-36377HIGHCVSS 6.7EG 7.82022-11-11
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privil…
- CVE-2022-36391MEDIUMCVSS 6.7EG 6.72023-05-10
Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36397HIGHCVSS 7.3EG 7.82023-02-16
Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36438HIGHCVSS 7.8EG 7.82022-10-18
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface…
- CVE-2022-36439MEDIUMCVSS 6.0EG 6.02022-10-18
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS Sys…
- CVE-2022-36640CRITICALCVSS 9.8EG 9.82022-09-02
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If In…
- CVE-2022-36803HIGHCVSS 8.8EG 8.82022-10-14
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was re…
- CVE-2022-37003CRITICALCVSS 9.8EG 9.82022-08-10
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
- CVE-2022-37006HIGHCVSS 7.5EG 7.52022-08-10
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
- CVE-2022-37018HIGHCVSS 8.4EG 8.42022-12-12
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.
- CVE-2022-37030HIGHCVSS 7.8EG 7.82022-08-04
Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM modul…
- CVE-2022-37173HIGHCVSS 7.8EG 7.82022-08-30
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
- CVE-2022-3758MEDIUMCVSS 5.4EG 5.42023-03-09
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorise…
- CVE-2022-38466HIGHCVSS 7.8EG 7.82022-09-13
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator.
- CVE-2022-38583HIGHCVSS 7.8EG 7.82023-04-28
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folde…
- CVE-2022-38764HIGHCVSS 7.8EG 7.82022-09-19
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.
- CVE-2022-3884HIGHCVSS 7.3EG 7.32023-02-28
Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local users to read and write specific files.This issue affects Hitachi Ops Center Analyzer: fr…
- CVE-2022-39081MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39082MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39083MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39084MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39085MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39086MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39087MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39088MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-40109CRITICALCVSS 9.8EG 9.82022-09-06
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
- CVE-2022-40187HIGHCVSS 8.0EG 8.02022-10-13
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access …
- CVE-2022-4020HIGHCVSS 8.1EG 8.22022-11-28
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
- CVE-2022-40232HIGHCVSS 6.3EG 8.82023-02-17
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should not have access to due to improper permission controls. IBM X-Force ID: 235597.
- CVE-2022-4039HIGHCVSS 8.0EG 8.02023-09-22
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modi…
- CVE-2022-40971MEDIUMCVSS 6.7EG 6.72023-05-10
Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41414MEDIUMCVSS 5.3EG 5.32022-10-07
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
- CVE-2022-41572CRITICALCVSS 9.8EG 9.82025-01-07
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.
- CVE-2022-41687MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41748MEDIUMCVSS 6.7EG 6.72022-10-10
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affect…
- CVE-2022-41943CRITICALCVSS 9.0EG 9.02022-11-22
sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default.…
- CVE-2022-42127MEDIUMCVSS 5.3EG 5.32022-11-15
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned…
- CVE-2022-42128MEDIUMCVSS 5.3EG 5.32022-11-15
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExtern…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →