CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 6 of 38
- CVE-2018-1141HIGHCVSS 7.0EG 7.02018-03-20
When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the dire…
- CVE-2018-11453HIGHCVSS 7.8EG 7.82018-08-07
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) a…
- CVE-2018-11454HIGHCVSS 8.6EG 8.62018-08-07
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) a…
- CVE-2018-1164CRITICALCVSS 9.8EG 9.82018-02-21
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exis…
- CVE-2018-11642HIGHCVSS 7.8EG 7.82018-07-03
Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root user.
- CVE-2018-1168HIGHCVSS 7.8EG 7.82018-02-21
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exp…
- CVE-2018-11792CRITICALCVSS 9.8EG 9.82018-10-24
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database…
- CVE-2018-11907HIGHCVSS 7.8EG 7.82018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /firmware/ which presents a potential issue.
- CVE-2018-11908HIGHCVSS 7.8EG 7.82018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /data/ which presents a potential issue.
- CVE-2018-11909HIGHCVSS 7.8EG 7.82018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /cache/ which presents a potential issue.
- CVE-2018-11910HIGHCVSS 7.8EG 7.82018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /persist/ which presents a potential issue.
- CVE-2018-11913HIGHCVSS 7.8EG 7.82018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may lead to potential security issue.
- CVE-2018-11914HIGHCVSS 7.8EG 7.82018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /systemrw/ which presents a potential security.
- CVE-2018-11951MEDIUMCVSS 5.5EG 5.52018-10-26
Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 845, SD 850.
- CVE-2018-11964HIGHCVSS 7.8EG 7.82018-12-20
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd may lead to security issue.
- CVE-2018-1197HIGHCVSS 8.5EG 8.52018-03-19
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials.
- CVE-2018-12027HIGHCVSS 8.8EG 8.82018-06-17
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain …
- CVE-2018-12028HIGHCVSS 7.8EG 7.82018-06-17
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's proc…
- CVE-2018-1203MEDIUMCVSS 6.7EG 6.72018-03-26
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used b…
- CVE-2018-12131HIGHCVSS 7.8EG 7.82018-10-10
Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticated user to potentially escalate privilege via local access.
- CVE-2018-12148HIGHCVSS 7.8EG 7.82018-09-12
Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.
- CVE-2018-12162HIGHCVSS 7.8EG 7.82018-09-12
Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access.
- CVE-2018-12168HIGHCVSS 7.8EG 7.82018-09-12
Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potentially execute code as administrator via local access.
- CVE-2018-12173HIGHCVSS 7.6EG 7.62018-10-10
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in info…
- CVE-2018-12177HIGHCVSS 7.8EG 7.82019-01-10
Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.0.7 may allow an authorized user to potentially enable escalation of privilege via local access.
- CVE-2018-12200MEDIUMCVSS 6.7EG 6.72019-03-14
Insufficient access control in Intel(R) Capability Licensing Service before version 1.50.638.1 may allow an unprivileged user to potentially escalate privileges via local access.
- CVE-2018-12209LOWCVSS 3.3EG 3.32019-03-14
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and …
- CVE-2018-12217LOWCVSS 2.3EG 2.32019-03-14
Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) an…
- CVE-2018-12223MEDIUMCVSS 6.3EG 6.32019-03-14
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and …
- CVE-2018-12259MEDIUMCVSS 6.8EG 6.82018-06-12
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise.
- CVE-2018-12296HIGHCVSS 7.5EG 7.52019-05-13
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
- CVE-2018-1231HIGHCVSS 8.8EG 8.82018-03-27
Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authentica…
- CVE-2018-12335HIGHCVSS 7.3EG 7.32018-06-17
Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollm…
- CVE-2018-12357MEDIUMCVSS 6.5EG 6.52019-08-15
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
- CVE-2018-12396MEDIUMCVSS 6.5EG 6.52019-02-28
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. …
- CVE-2018-12457HIGHCVSS 8.8EG 8.82018-06-15
expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
- CVE-2018-12466MEDIUMCVSS 4.4EG 6.52018-08-01
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
- CVE-2018-12467MEDIUMCVSS 6.0EG 6.52018-08-01
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
- CVE-2018-12546MEDIUMCVSS 6.5EG 6.52019-03-27
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in…
- CVE-2018-12615MEDIUMCVSS 5.3EG 5.32018-06-21
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementar…
- CVE-2018-12642HIGHCVSS 7.5EG 7.52018-06-22
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
- CVE-2018-1267HIGHCVSS 8.1EG 8.12018-03-27
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications…
- CVE-2018-12922HIGHCVSS 7.5EG 7.52018-06-28
Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelnet.htm URI.
- CVE-2018-12979MEDIUMCVSS 6.5EG 6.52018-07-12
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.
- CVE-2018-13025MEDIUMCVSS 4.9EG 4.92018-06-29
protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admin/photo/delpic picname parameter.
- CVE-2018-13110HIGHCVSS 7.5EG 7.52018-07-06
All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain access to the command line interface (CLI) if previously disabled by the ISP, escalate their…
- CVE-2018-13122MEDIUMCVSS 6.5EG 6.52018-07-03
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI.
- CVE-2018-1315LOWCVSS 3.7EG 3.72018-04-05
In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on the cluster where the command is run from…
- CVE-2018-13321HIGHCVSS 8.8EG 8.82018-11-26
Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "method" parameter.
- CVE-2018-13355MEDIUMCVSS 6.5EG 6.52018-11-27
Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →