CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 18 of 38
- CVE-2020-8473HIGHCVSS 7.3EG 7.32020-04-29
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully…
- CVE-2020-8602HIGHCVSS 7.2EG 7.22020-08-27
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to…
- CVE-2020-8635HIGHCVSS 7.8EG 7.82020-03-07
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges withi…
- CVE-2020-8731HIGHCVSS 8.8EG 8.82020-08-13
Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local acc…
- CVE-2020-8768CRITICALCVSS 9.4EG 9.42020-02-17
An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be disco…
- CVE-2020-8908LOWCVSS 3.3EG 3.32020-12-10
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(…
- CVE-2020-9024CRITICALCVSS 9.8EG 9.82020-02-17
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.
- CVE-2020-9048HIGHCVSS 7.1EG 8.12020-10-08
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unus…
- CVE-2020-9382MEDIUMCVSS 5.4EG 5.42020-02-24
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.
- CVE-2020-9470HIGHCVSS 7.8EG 7.82020-03-07
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session …
- CVE-2020-9671CRITICALCVSS 9.8EG 9.82020-07-17
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
- CVE-2020-9851MEDIUMCVSS 5.5EG 5.52020-06-09
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to modify protected parts of the file system.
- CVE-2021-0055HIGHCVSS 7.8EG 7.82021-06-09
Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0056HIGHCVSS 7.8EG 7.82021-06-09
Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0064HIGHCVSS 7.8EG 7.82021-11-17
Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0077HIGHCVSS 7.8EG 7.82021-06-09
Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0102HIGHCVSS 7.8EG 7.82021-06-09
Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.
- CVE-2021-0105HIGHCVSS 7.3EG 7.32021-06-09
Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclosure and denial of service via adjacent access.
- CVE-2021-0109HIGHCVSS 7.8EG 7.82021-02-17
Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0304MEDIUMCVSS 5.5EG 5.52021-01-11
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interac…
- CVE-2021-0334HIGHCVSS 7.8EG 7.82021-02-10
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. …
- CVE-2021-0336HIGHCVSS 7.8EG 7.82021-02-10
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges neede…
- CVE-2021-0372HIGHCVSS 7.8EG 7.82021-03-10
In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not ne…
- CVE-2021-0390HIGHCVSS 7.8EG 7.82021-03-10
In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. This could lead to local escalation of privilege by a background user on the same device wi…
- CVE-2021-0477HIGHCVSS 7.8EG 7.82021-06-11
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interact…
- CVE-2021-0539HIGHCVSS 7.8EG 7.82021-06-22
In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution …
- CVE-2021-0552MEDIUMCVSS 5.5EG 5.52021-06-22
In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed …
- CVE-2021-0570HIGHCVSS 7.8EG 7.82021-06-22
In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction i…
- CVE-2021-0572MEDIUMCVSS 5.5EG 5.52021-06-22
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed fo…
- CVE-2021-0692HIGHCVSS 7.8EG 7.82021-10-06
In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- CVE-2021-0904MEDIUMCVSS 6.7EG 6.72021-12-15
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
- CVE-2021-0931MEDIUMCVSS 5.5EG 5.52021-12-15
In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data filtering. This could lead to local information disclosure with User execution privileges needed. User interaction is …
- CVE-2021-1126MEDIUMCVSS 5.5EG 5.52021-01-13
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text st…
- CVE-2021-1784HIGHCVSS 7.5EG 7.52021-09-08
A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may…
- CVE-2021-20077MEDIUMCVSS 6.7EG 6.72021-03-19
Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged …
- CVE-2021-20172HIGHCVSS 7.8EG 7.82021-12-30
All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local a…
- CVE-2021-20264HIGHCVSS 7.8EG 7.82021-10-06
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest th…
- CVE-2021-20326MEDIUMCVSS 6.5EG 6.52021-04-30
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.
- CVE-2021-20355MEDIUMCVSS 5.3EG 5.32022-06-24
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitiv…
- CVE-2021-20416MEDIUMCVSS 5.3EG 5.32021-07-07
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive in…
- CVE-2021-20423HIGHCVSS 8.8EG 8.82021-07-13
IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force ID: 196308.
- CVE-2021-20429MEDIUMCVSS 5.3EG 5.32021-05-14
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force ID: 196334.
- CVE-2021-20526MEDIUMCVSS 5.3EG 5.32021-10-27
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. I…
- CVE-2021-20643HIGHCVSS 7.5EG 7.52021-02-12
Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected device by processing a specially crafted request.
- CVE-2021-20874HIGHCVSS 7.5EG 7.52021-12-24
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated at…
- CVE-2021-20996MEDIUMCVSS 5.3EG 5.32021-05-13
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.
- CVE-2021-21177MEDIUMCVSS 6.5EG 6.52021-03-09
Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2021-21364MEDIUMCVSS 5.3EG 5.32021-03-11
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before versio…
- CVE-2021-21494MEDIUMCVSS 4.8EG 4.82021-01-04
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
- CVE-2021-21567HIGHCVSS 7.8EG 7.82021-08-10
Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →