CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,886 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 31 of 38
- CVE-2024-38864LOWCVSS 3.3EG 3.32024-12-19
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.
- CVE-2024-39709HIGHCVSS 7.8EG 7.82024-11-13
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
- CVE-2024-39875MEDIUMCVSS 4.3EG 4.32024-07-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows authenticated, low privilege users with the 'Manage own remote connections' permission to retrieve details about…
- CVE-2024-39967MEDIUMCVSS 6.5EG 6.52025-01-15
Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.
- CVE-2024-41171HIGHCVSS 8.8EG 8.82024-09-10
A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions < V6.24). Affected devices do not properly enforce access r…
- CVE-2024-41647CRITICALCVSS 9.8EG 9.82024-12-06
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.
- CVE-2024-41685HIGHCVSS 7.5EG 7.52024-07-26
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting t…
- CVE-2024-41720HIGHCVSS 8.0EG 8.02024-08-05
Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the configuration of the device.
- CVE-2024-41820MEDIUMCVSS 6.0EG 6.02024-08-05
Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a malicious user can access the worker node which has kubean's deployment, he/she can ab…
- CVE-2024-41954MEDIUMCVSS 5.3EG 5.32024-07-31
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting t…
- CVE-2024-41970MEDIUMCVSS 5.7EG 5.72024-11-18
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
- CVE-2024-41974HIGHCVSS 7.1EG 7.12024-11-18
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
- CVE-2024-42449HIGHCVSS 7.1EG 7.12024-12-04
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.
- CVE-2024-43199HIGHCVSS 7.8EG 8.82024-08-07
Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.
- CVE-2024-44575LOWCVSS 3.7EG 3.72024-09-11
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
- CVE-2024-44729HIGHCVSS 7.5EG 7.52024-10-11
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
- CVE-2024-45041HIGHCVSS 8.3EG 8.32024-09-09
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This…
- CVE-2024-45164HIGHCVSS 7.1EG 7.12024-11-04
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admi…
- CVE-2024-45497HIGHCVSS 7.6EG 7.62024-12-31
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credential…
- CVE-2024-45655MEDIUMCVSS 5.5EG 5.52025-06-03
IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
- CVE-2024-45657MEDIUMCVSS 5.0EG 5.02025-02-04
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
- CVE-2024-45841MEDIUMCVSS 6.5EG 6.52024-12-05
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific fi…
- CVE-2024-46060HIGHCVSS 7.8EG 7.82025-12-17
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This …
- CVE-2024-46062HIGHCVSS 7.8EG 7.82025-12-17
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This…
- CVE-2024-46881HIGHCVSS 7.1EG 7.12025-01-26
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to version…
- CVE-2024-46897LOWCVSS 3.8EG 3.82024-10-18
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of table management may obtain and/or alter the information of the unautho…
- CVE-2024-47104MEDIUMCVSS 6.8EG 6.82024-12-18
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the…
- CVE-2024-47475MEDIUMCVSS 5.0EG 5.02025-01-06
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service.
- CVE-2024-47783HIGHCVSS 7.8EG 7.82024-11-12
A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or m…
- CVE-2024-47808HIGHCVSS 8.4EG 8.42024-11-12
A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. Thi…
- CVE-2024-47833MEDIUMCVSS 6.5EG 6.52024-10-09
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been …
- CVE-2024-49385MEDIUMCVSS 5.5EG 5.52025-01-02
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (Windows) before build 42575.
- CVE-2024-50590HIGHCVSS 7.8EG 7.82024-11-08
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory …
- CVE-2024-51448MEDIUMCVSS 6.7EG 6.72025-01-18
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-pri…
- CVE-2024-5163CRITICALCVSS 9.8EG 9.82024-06-17
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
- CVE-2024-52328LOWCVSS 2.3EG 2.32025-01-23
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera i…
- CVE-2024-53351CRITICALCVSS 9.8EG 9.82025-03-21
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
- CVE-2024-53931CRITICALCVSS 9.1EG 9.12025-01-06
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.glit…
- CVE-2024-53932CRITICALCVSS 9.1EG 9.12025-01-06
The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a …
- CVE-2024-54159MEDIUMCVSS 4.1EG 4.12024-11-29
stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.
- CVE-2024-54910MEDIUMCVSS 4.7EG 4.72025-01-10
Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
- CVE-2024-55411HIGHCVSS 8.8EG 8.82025-01-07
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.
- CVE-2024-55955MEDIUMCVSS 6.7EG 6.72024-12-31
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an atta…
- CVE-2024-5618CRITICALCVSS 9.9EG 9.92024-07-18
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: befo…
- CVE-2024-57068HIGHCVSS 7.5EG 7.52025-02-05
A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
- CVE-2024-57520CRITICALCVSS 9.8EG 9.82025-02-05
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outsid…
- CVE-2024-57547HIGHCVSS 7.5EG 7.52025-01-27
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.
- CVE-2024-5915HIGHCVSS 7.8EG 7.82024-08-14
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
- CVE-2024-5930HIGHCVSS 7.8EG 7.82024-08-21
VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first…
- CVE-2024-6360CRITICALCVSS 9.8EG 9.82024-10-02
Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through …
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →