CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2021-25653 HIGH
Avaya Aura Appliance Virtualization Platform 8.0.0.0-8.1.3.1 - Privilege Escalation
CVSS 8.0
CVE-2021-25651 HIGH
Avaya Aura Utility Services 7.0-7.1.2 - Privilege Escalation
CVSS 8.0
CVE-2021-25650 HIGH
Avaya Aura Utility Services 7.0-7.1.3 - Privilege Escalation via Crafted Script Execution
CVSS 7.7
CVE-2021-1528 HIGH
Cisco SD-WAN Software - Privilege Escalation
CVSS 7.8
CVE-2021-0256 MEDIUM
Juniper Networks Junos OS - Info Disclosure
CVSS 5.5
CVE-2021-0255 MEDIUM
Juniper Junos OS - Local Privilege Escalation via ethtraceroute Setuid Binary
CVSS 5.5
CVE-2021-27454 HIGH
GE Reason DR60 Firmware < 02a04.1 - Improper Privilege Management
CVSS 7.8
CVE-2021-27448 HIGH
MU320E <v04A00.1 - Privilege Escalation
CVSS 7.8
CVE-2021-0223 HIGH
Juniper Junos OS - Authenticated Local Privilege Escalation via telnetd.real Setuid Abuse
CVSS 7.8
CVE-2021-0204 HIGH
Juniper Networks Junos OS - Info Disclosure
CVSS 7.8
CVE-2020-36868 HIGH
Nagios XI <5.7.3 - Privilege Escalation
CVSS 7.8
CVE-2020-26074 HIGH
Cisco SD-WAN vManage Software - Privilege Escalation
CVSS 7.8
CVE-2020-27826 MEDIUM
Keycloak <12.0.0 - Privilege Escalation
CVSS 4.2
CVE-2020-26278 MEDIUM
Weave Net <2.8.0 - Privilege Escalation
CVSS 5.8
CVE-2020-14386 MEDIUM
Linux Kernel < 4.9.239 - Privilege Escalation via Memory Corruption
CVSS 6.7
CVE-2020-10056 HIGH
Siemens License Management Utility < 2.4 - Authenticated Privilege Escalation via lmgrd Service Configuration
CVSS 7.8
CVE-2020-10290 MEDIUM
Universal Robots - RCE
CVSS 6.8
CVE-2020-14493 HIGH
OpenClinic GA <5.89.05b - SQL Injection
CVSS 8.8
CVE-2020-2023 LOW
Kata Containers <1.11.1, <1.10.5, <=1.9 - Remote Code Execution
CVSS 3.8
CVE-2020-7252 MEDIUM
McAfee Data eXchange Layer < 6.0.0 - Unquoted Service Path Arbitrary Code Execution
CVSS 4.2
CVE-2019-15790 LOW
Apport - Privilege Escalation via PID Recycling
CVSS 2.8
CVE-2019-16784 HIGH
PyInstaller <3.6 - Privilege Escalation
CVSS 7.0
CVE-2019-16767 MEDIUM
ezmaster < 5.2.11 - Execution with Unnecessary Privileges
CVSS 6.6
CVE-2019-16765 HIGH
Microsoft CodeQL < 1.0.1 - Arbitrary Code Execution via Workspace Directory Traversal
CVSS 7.4
CVE-2019-10168 HIGH
libvirt <4.10.1-5.4.1 - Code Injection
CVSS 7.8
Details
Vulnerabilities 341
Exploit Likelihood Medium