CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,886 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 30 of 38
- CVE-2024-21915CRITICALCVSS 9.0EG 9.02024-02-16
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administra…
- CVE-2024-22016HIGHCVSS 7.8EG 7.82024-02-02
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.
- CVE-2024-22029HIGHCVSS 7.8EG 7.82024-10-16
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
- CVE-2024-22236LOWCVSS 3.3EG 3.32024-01-31
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permission…
- CVE-2024-22334MEDIUMCVSS 4.4EG 4.42024-04-12
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom s…
- CVE-2024-23223MEDIUMCVSS 6.2EG 6.22024-01-23
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access sensitive user data.
- CVE-2024-23908MEDIUMCVSS 6.7EG 6.72024-08-14
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-24117CRITICALCVSS 9.8EG 9.82024-10-02
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
- CVE-2024-24740MEDIUMCVSS 5.3EG 5.32024-02-13
SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain conditions, allows an attacker to access information which could ot…
- CVE-2024-24910HIGHCVSS 7.3EG 7.32024-04-18
A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain t…
- CVE-2024-24912MEDIUMCVSS 6.7EG 6.72024-05-01
A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged …
- CVE-2024-25561MEDIUMCVSS 6.7EG 6.72024-08-14
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-25644MEDIUMCVSS 5.3EG 5.32024-03-12
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the applicati…
- CVE-2024-25645MEDIUMCVSS 5.3EG 5.32024-03-12
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integri…
- CVE-2024-25646HIGHCVSS 7.7EG 7.72024-04-09
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impac…
- CVE-2024-25956MEDIUMCVSS 5.5EG 5.52024-03-26
Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system in…
- CVE-2024-27108MEDIUMCVSS 6.8EG 6.82024-05-14
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
- CVE-2024-27294HIGHCVSS 7.3EG 7.32024-02-29
dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version…
- CVE-2024-27883MEDIUMCVSS 4.4EG 4.42024-07-29
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
- CVE-2024-28163MEDIUMCVSS 5.3EG 5.32024-03-12
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on I…
- CVE-2024-28589MEDIUMCVSS 6.7EG 6.72024-04-03
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during …
- CVE-2024-28745LOWCVSS 3.3EG 3.32024-03-18
Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing another app installed on the user's device to access an arbitrary URL on 'ABEMA' App for Android via Intent. If this vulner…
- CVE-2024-28827HIGHCVSS 8.8EG 8.82024-07-10
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.
- CVE-2024-28955MEDIUMCVSS 5.9EG 5.92024-11-26
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, …
- CVE-2024-2905MEDIUMCVSS 6.2EG 6.22024-04-25
A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than rec…
- CVE-2024-29078HIGHCVSS 7.5EG 7.52024-05-28
Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to the product to alter the product settings.
- CVE-2024-29187HIGHCVSS 7.3EG 7.32024-03-24
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple…
- CVE-2024-29869MEDIUMCVSS 5.5EG 5.52025-01-28
Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive infor…
- CVE-2024-29964MEDIUMCVSS 5.7EG 5.72024-04-19
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.
- CVE-2024-30208MEDIUMCVSS 6.3EG 6.32024-05-14
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All ver…
- CVE-2024-30369HIGHCVSS 7.8EG 7.82024-06-06
A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. An attacker must first obtain the abil…
- CVE-2024-30413HIGHCVSS 7.5EG 7.52024-04-07
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-31202HIGHCVSS 7.8EG 8.42024-07-31
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
- CVE-2024-32010HIGHCVSS 7.8EG 7.82025-11-11
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to con…
- CVE-2024-32014MEDIUMCVSS 4.7EG 4.72025-11-11
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain ad…
- CVE-2024-32478MEDIUMCVSS 6.9EG 6.92024-04-19
Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This allows user 1001 on a multi-user system can replace binary and gain other users' privil…
- CVE-2024-3250MEDIUMCVSS 6.5EG 6.52024-04-04
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root…
- CVE-2024-33435CRITICALCVSS 9.8EG 9.82024-04-29
Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.…
- CVE-2024-33499CRITICALCVSS 9.1EG 9.12024-05-14
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All ver…
- CVE-2024-3375CRITICALCVSS 9.4EG 9.42024-04-29
Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dialogue: from v1.83 before v1.83.1 or v1.84.
- CVE-2024-36276MEDIUMCVSS 6.7EG 6.72024-11-13
Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-36294MEDIUMCVSS 6.7EG 6.72024-11-13
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-3668HIGHCVSS 8.8EG 8.82024-06-08
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a regi…
- CVE-2024-36821HIGHCVSS 6.8EG 8.82024-06-11
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
- CVE-2024-37087MEDIUMCVSS 5.3EG 5.32024-06-25
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
- CVE-2024-37369HIGHCVSS 8.8EG 8.82024-06-14
A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system.
- CVE-2024-37574HIGHCVSS 8.2EG 8.22024-12-04
The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivi…
- CVE-2024-38337CRITICALCVSS 9.1EG 9.12025-01-19
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments.
- CVE-2024-38456HIGHCVSS 7.8EG 7.82024-09-03
HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) can exploit the weak folder and file permissi…
- CVE-2024-38646MEDIUMCVSS 6.0EG 6.02024-11-22
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or m…
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →