CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,886 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 28 of 38
- CVE-2023-35841HIGHCVSS 7.8EG 7.82024-05-14
Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
- CVE-2023-35870MEDIUMCVSS 6.3EG 6.32023-07-11
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and i…
- CVE-2023-36465CRITICALCVSS 9.1EG 9.12023-10-06
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allo…
- CVE-2023-36633MEDIUMCVSS 5.4EG 5.42023-11-14
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTT…
- CVE-2023-37237MEDIUMCVSS 6.5EG 6.52023-06-29
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
- CVE-2023-38037MEDIUMCVSS 5.5EG 5.52025-01-09
ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same syst…
- CVE-2023-38497HIGHCVSS 7.9EG 7.92023-08-04
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the use…
- CVE-2023-38541MEDIUMCVSS 6.7EG 6.72024-01-19
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via loc…
- CVE-2023-38557HIGHCVSS 8.2EG 8.22023-09-14
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalat…
- CVE-2023-38640MEDIUMCVSS 6.6EG 6.62023-10-10
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.22). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to read…
- CVE-2023-38991MEDIUMCVSS 5.4EG 5.42023-08-04
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.
- CVE-2023-39003HIGHCVSS 7.5EG 7.52023-08-09
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
- CVE-2023-39004CRITICALCVSS 9.8EG 9.82023-08-09
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to priv…
- CVE-2023-39005HIGHCVSS 7.5EG 7.52023-08-09
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
- CVE-2023-3915MEDIUMCVSS 6.5EG 6.52023-09-01
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on …
- CVE-2023-39230MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-39338MEDIUMCVSS 6.8EG 6.82025-07-12
Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to access that service. It does not enable the user to authenticate to or use the servic…
- CVE-2023-40302CRITICALCVSS 9.1EG 9.12023-12-07
NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability
- CVE-2023-40361HIGHCVSS 7.8EG 7.82023-10-20
SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for…
- CVE-2023-40516HIGHCVSS 7.8EG 7.82024-05-03
LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of LG Simple Editor. An attacker must first obtain the ab…
- CVE-2023-40622CRITICALCVSS 9.9EG 9.92023-09-12
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation…
- CVE-2023-40754HIGHCVSS 8.8EG 8.82023-08-28
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- CVE-2023-41295MEDIUMCVSS 5.3EG 5.32023-09-25
Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim.
- CVE-2023-41776HIGHCVSS 7.8EG 7.82024-01-03
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.
- CVE-2023-42189HIGHCVSS 7.5EG 7.52023-10-10
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smar…
- CVE-2023-4228MEDIUMCVSS 4.3EG 4.32023-08-24
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks,…
- CVE-2023-42489CRITICALCVSS 9.8EG 9.82023-10-25
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
- CVE-2023-42861MEDIUMCVSS 6.5EG 6.52023-10-25
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's credentials can unlock another standard user's locked screen on the same Mac.
- CVE-2023-42924MEDIUMCVSS 5.5EG 5.52023-12-12
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app may be able to access sensitive user data.
- CVE-2023-4332HIGHCVSS 7.5EG 7.52023-08-15
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
- CVE-2023-4383HIGHCVSS 7.8EG 7.82023-08-16
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation leads to incorrect execution-assigned permissions. The attack…
- CVE-2023-44120HIGHCVSS 7.8EG 7.82024-01-09
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administrative account to execute several entries as root user. This could allow an authenticated l…
- CVE-2023-44201MEDIUMCVSS 5.5EG 5.52023-10-13
An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker to read configuration changes without having the permissions…
- CVE-2023-44387MEDIUMCVSS 6.5EG 6.52023-10-05
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permission…
- CVE-2023-45205HIGHCVSS 7.8EG 7.82023-10-10
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to inje…
- CVE-2023-45364MEDIUMCVSS 5.3EG 5.32023-10-09
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revi…
- CVE-2023-45369MEDIUMCVSS 4.3EG 4.32023-10-09
An issue was discovered in the PageTriage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. Usernames of hidden users are exposed.
- CVE-2023-4565MEDIUMCVSS 5.3EG 5.32023-09-27
Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.
- CVE-2023-46141CRITICALCVSS 9.8EG 9.82023-12-14
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
- CVE-2023-46142HIGHCVSS 8.8EG 8.82023-12-14
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
- CVE-2023-46449HIGHCVSS 8.8EG 8.82023-10-26
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
- CVE-2023-4665HIGHCVSS 8.8EG 8.82023-09-15
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.
- CVE-2023-47564HIGHCVSS 8.0EG 8.02024-02-02
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have alread…
- CVE-2023-47712HIGHCVSS 7.8EG 7.82024-05-14
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
- CVE-2023-4777MEDIUMCVSS 4.3EG 4.32023-09-08
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential…
- CVE-2023-47801MEDIUMCVSS 4.7EG 4.72023-11-13
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API e…
- CVE-2023-48087MEDIUMCVSS 5.4EG 5.42023-11-15
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.
- CVE-2023-48714MEDIUMCVSS 4.3EG 4.32024-01-23
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` us…
- CVE-2023-49257HIGHCVSS 8.8EG 8.82024-01-12
An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.
- CVE-2023-49578LOWCVSS 3.5EG 3.52023-12-12
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confident…
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →