CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,884 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 4 of 38
- CVE-2017-6950CRITICALCVSS 9.8EG 9.82017-03-23
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.
- CVE-2017-7146MEDIUMCVSS 5.3EG 5.32017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Security" component. It allows attackers to track users across installs via a crafted app that leverages Keychain data mishandling.
- CVE-2017-7199HIGHCVSS 7.8EG 7.82017-03-23
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
- CVE-2017-7307MEDIUMCVSS 6.8EG 6.82017-04-04
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file.
- CVE-2017-7337CRITICALCVSS 9.1EG 9.12017-05-27
An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName par…
- CVE-2017-7471CRITICALCVSS 9.0EG 9.02018-07-09
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged use…
- CVE-2017-7493HIGHCVSS 7.8EG 7.82017-05-17
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode.…
- CVE-2017-7560MEDIUMCVSS 5.5EG 5.52017-09-13
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.
- CVE-2017-7563HIGHCVSS 8.1EG 8.12017-06-07
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one …
- CVE-2017-7821CRITICALCVSS 9.8EG 9.82018-06-11
A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific user interaction for the file download and open actions. This could be used to trigger kn…
- CVE-2017-7849MEDIUMCVSS 5.5EG 5.52017-04-19
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
- CVE-2017-7850HIGHCVSS 7.8EG 7.82017-04-19
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
- CVE-2017-7889HIGHCVSS 7.8EG 7.82017-04-17
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocatio…
- CVE-2017-8158MEDIUMCVSS 6.5EG 6.52017-11-22
FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine. An authenticated attacker could create a large number of virtual machine (VM…
- CVE-2017-8391MEDIUMCVSS 5.5EG 5.52017-05-06
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive informa…
- CVE-2017-8449MEDIUMCVSS 5.9EG 5.92017-06-16
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.
- CVE-2017-8450HIGHCVSS 7.5EG 7.52017-06-16
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
- CVE-2017-8665HIGHCVSS 7.8EG 7.82017-08-15
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."
- CVE-2017-8856CRITICALCVSS 9.8EG 9.82017-05-09
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the 'bprd' process.
- CVE-2017-8857CRITICALCVSS 9.8EG 9.82017-05-09
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command execution using the 'bprd' process.
- CVE-2017-8858CRITICALCVSS 9.8EG 9.82017-05-09
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' process.
- CVE-2017-9079MEDIUMCVSS 4.7EG 4.72017-05-19
Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are…
- CVE-2017-9136HIGHCVSS 7.5EG 7.52017-05-21
An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user. The attacker can d…
- CVE-2017-9268MEDIUMCVSS 4.4EG 6.52018-03-01
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of…
- CVE-2017-9462HIGHCVSS 8.8EG 8.82017-06-06
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
- CVE-2017-9479CRITICALCVSS 9.8EG 9.82017-07-31
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd se…
- CVE-2017-9482CRITICALCVSS 9.8EG 9.82017-07-31
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root access to the Network Processor (NP) Linux system by enabling a TELNET daemon (through CVE-2…
- CVE-2017-9494MEDIUMCVSS 5.3EG 5.32017-07-31
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet.
- CVE-2017-9514HIGHCVSS 8.8EG 8.82017-10-12
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit …
- CVE-2017-9602CRITICALCVSS 9.8EG 9.82017-06-16
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this function…
- CVE-2017-9606HIGHCVSS 7.3EG 7.32017-06-15
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction wi…
- CVE-2017-9615CRITICALCVSS 9.8EG 9.82017-06-26
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.
- CVE-2017-9626CRITICALCVSS 9.8EG 9.82019-03-27
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication.
- CVE-2017-9780HIGHCVSS 7.8EG 7.82017-06-21
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a lo…
- CVE-2017-9792MEDIUMCVSS 6.5EG 6.52017-10-04
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table ma…
- CVE-2017-9958HIGHCVSS 7.8EG 7.82017-09-26
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the …
- CVE-2018-0088MEDIUMCVSS 6.7EG 6.72018-01-18
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow an authenticated, local attacker to impact the stability of the device. This could result i…
- CVE-2018-0089HIGHCVSS 7.5EG 7.52018-01-18
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconn…
- CVE-2018-0352MEDIUMCVSS 6.7EG 6.72018-06-07
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to elevate their privilege level to root. The attacker must have valid user creden…
- CVE-2018-0392MEDIUMCVSS 5.5EG 5.52018-07-18
A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient access control permissions (i.e., World-Readable). An attacker co…
- CVE-2018-0422HIGHCVSS 7.3EG 7.32018-10-05
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. Th…
- CVE-2018-0449MEDIUMCVSS 4.2EG 4.22019-01-10
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated priv…
- CVE-2018-0752HIGHCVSS 7.8EG 7.82018-01-04
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way th…
- CVE-2018-0982HIGHCVSS 7.0EG 7.02018-06-14
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
- CVE-2018-1000025HIGHCVSS 8.1EG 8.12018-02-09
Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that can result in JWT with any email addres…
- CVE-2018-1000071HIGHCVSS 7.5EG 7.52018-03-13
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
- CVE-2018-1000072HIGHCVSS 7.5EG 7.52018-03-13
iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack…
- CVE-2018-1000080MEDIUMCVSS 6.5EG 6.52018-03-13
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is ma…
- CVE-2018-1000132CRITICALCVSS 9.1EG 9.12018-03-14
Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability…
- CVE-2018-1000158HIGHCVSS 8.8EG 8.82018-04-18
cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Res…
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →