CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 15 of 38
- CVE-2020-13431HIGHCVSS 7.8EG 7.82020-06-16
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
- CVE-2020-13696MEDIUMCVSS 4.4EG 4.42020-06-08
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local …
- CVE-2020-13866HIGHCVSS 7.8EG 7.82020-06-08
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
- CVE-2020-13912HIGHCVSS 7.3EG 7.32020-06-07
SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.
- CVE-2020-13915HIGHCVSS 7.5EG 7.52020-07-28
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R…
- CVE-2020-14263LOWCVSS 3.9EG 3.92021-10-21
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
- CVE-2020-14335MEDIUMCVSS 5.5EG 5.52021-06-02
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The highest threat from thi…
- CVE-2020-14987HIGHCVSS 7.2EG 7.22021-03-11
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts …
- CVE-2020-15250MEDIUMCVSS 4.4EG 4.42020-10-12
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because o…
- CVE-2020-15328MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
- CVE-2020-15329MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
- CVE-2020-15385MEDIUMCVSS 5.4EG 5.42021-06-09
Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders, and hidden files, and can create directories without permis…
- CVE-2020-15388MEDIUMCVSS 6.5EG 6.52022-03-18
A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files.
- CVE-2020-15397HIGHCVSS 7.8EG 7.82020-06-30
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to e…
- CVE-2020-15528HIGHCVSS 7.8EG 7.82020-07-05
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity checks.
- CVE-2020-15529HIGHCVSS 7.8EG 7.82020-07-05
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and can be exploited by us…
- CVE-2020-15593HIGHCVSS 7.8EG 7.82020-07-27
SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among …
- CVE-2020-15595MEDIUMCVSS 4.3EG 4.32020-09-30
An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire …
- CVE-2020-15697MEDIUMCVSS 4.3EG 4.32020-07-15
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
- CVE-2020-15708CRITICALCVSS 9.3EG 9.32020-11-06
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
- CVE-2020-15776HIGHCVSS 8.8EG 8.82020-09-18
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could imp…
- CVE-2020-15838HIGHCVSS 8.8EG 8.82020-10-09
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
- CVE-2020-15871HIGHCVSS 8.8EG 8.82020-07-31
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
- CVE-2020-15910MEDIUMCVSS 4.7EG 4.72020-10-19
SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaS…
- CVE-2020-16202HIGHCVSS 7.8EG 7.82020-09-22
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.
- CVE-2020-16259CRITICALCVSS 9.8EG 9.82020-10-28
Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.
- CVE-2020-16261MEDIUMCVSS 6.8EG 6.82020-10-28
Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
- CVE-2020-16262HIGHCVSS 7.8EG 7.82020-10-28
Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
- CVE-2020-1694MEDIUMCVSS 4.9EG 4.92020-09-16
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.
- CVE-2020-16990MEDIUMCVSS 6.2EG 6.22020-11-11
Azure Sphere Information Disclosure Vulnerability
- CVE-2020-1701MEDIUMCVSS 6.5EG 6.52021-05-27
A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the con…
- CVE-2020-1704HIGHCVSS 7.0EG 7.02020-02-17
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could…
- CVE-2020-1705HIGHCVSS 7.0EG 7.02020-03-19
A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/template-service-broker-operator.…
- CVE-2020-1706HIGHCVSS 7.0EG 7.02020-03-09
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker…
- CVE-2020-1707HIGHCVSS 7.0EG 7.02020-03-20
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to t…
- CVE-2020-1709HIGHCVSS 7.0EG 7.82020-03-20
A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could u…
- CVE-2020-1736LOWCVSS 2.2EG 3.32020-03-16
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the fil…
- CVE-2020-17365HIGHCVSS 7.8EG 7.82020-09-24
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to c…
- CVE-2020-17402MEDIUMCVSS 6.5EG 6.52020-08-25
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4 (47270). An attacker must first obtain the ability to execute low-privileged code on the target system in ord…
- CVE-2020-17414HIGHCVSS 7.8EG 7.82020-10-13
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
- CVE-2020-17415HIGHCVSS 7.8EG 7.82020-10-13
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit …
- CVE-2020-1742HIGHCVSS 7.0EG 7.02021-06-07
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before…
- CVE-2020-17490MEDIUMCVSS 5.5EG 5.52020-11-06
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
- CVE-2020-17520MEDIUMCVSS 6.5EG 6.52020-12-18
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
- CVE-2020-17522MEDIUMCVSS 5.8EG 5.82021-01-26
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from…
- CVE-2020-1754MEDIUMCVSS 4.3EG 4.32022-08-05
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
- CVE-2020-18121HIGHCVSS 8.8EG 8.82021-08-30
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
- CVE-2020-18127MEDIUMCVSS 6.5EG 6.52021-08-30
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
- CVE-2020-20634MEDIUMCVSS 6.5EG 6.52020-08-21
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
- CVE-2020-21014MEDIUMCVSS 6.5EG 6.52021-10-01
emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →