CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2024-31891 HIGH
IBM Storage Scale GUI <5.2.1.1 - Privilege Escalation
CVSS 7.8
CVE-2024-28140 MEDIUM
Image Access GmbH Scan2Net < 7.42 - Unnecessary Privilege Escalation via Root-Level Browser Execution
CVSS 6.1
CVE-2024-28139 HIGH
Scan2Net < 7.42B - Privilege Escalation via Sudo Misconfiguration
CVSS 8.8
CVE-2024-49804 HIGH
IBM Security Verify Access Appliance <10.0.9 - Privilege Escalation
CVSS 7.8
CVE-2024-52799 HIGH
Argo Workflows Helm Chart <0.44.0 - Excessive Pod Exec Privileges
CVSS 8.2
CVE-2024-11075 HIGH
Incoming Goods Suite - Privilege Escalation
CVSS 8.8
CVE-2024-8781 HIGH
TR7 ASP <1.4.25.188 - Privilege Escalation
CVE-2024-51722 MEDIUM
SecuSUITE <5.0.420 - Privilege Escalation
CVSS 6.4
CVE-2024-48837 HIGH
Dell SmartFabric OS10 Software - Privilege Escalation
CVSS 7.8
CVE-2024-50590 HIGH
Elefant <unknown - Privilege Escalation
CVSS 7.8
CVE-2024-47903 MEDIUM
InterMesh Hybrid/ Fire <8.2.12/<7.2.12 - File Write
CVSS 5.8
CVE-2024-20420 MEDIUM
Cisco ATA 190 - Privilege Escalation
CVSS 5.4
CVE-2024-9473 HIGH
Palo Alto Networks GlobalProtect - Privilege Escalation via MSI Installer Repair Functionality
CVSS 7.8
CVE-2024-43583 HIGH
Windows 10 1507-22H2 and Windows 11 21H2 - Winlogon Elevation of Privilege
CVSS 7.8
CVE-2024-8903 MEDIUM
Acronis Cyber Protect Cloud Agent <38565 - Privilege Escalation
CVSS 4.7
CVE-2024-38813 HIGH KEV
VMware Cloud Foundation >=4.0 <5.2 and vCenter Server - Privilege Escalation to Root via Network Packet
CVSS 7.5
CVE-2024-8767 CRITICAL
Acronis Backup plugin for cPanel & WHM < 619 - Sensitive Data Disclosure and Manipulation via Unnecessary Privileges
CVSS 9.9
CVE-2024-7387 CRITICAL
OpenShift Builder - Command Injection via Path Traversal in BuildConfig Secret DestinationDir
CVSS 9.1
CVE-2024-35783 CRITICAL
SIMATIC BATCH V9.1, SIMATIC Information Server 2020 <V2020 SP2 Upda...
CVSS 9.1
CVE-2024-42024 HIGH
Veeam ONE 12.0.0.2498-12.2.0.4093 - Remote Code Execution via Agent Service Account
CVSS 8.8
CVE-2024-45034 HIGH
Apache Airflow <2.10.1 - Code Injection
CVSS 8.8
CVE-2024-5623 HIGH
B&R APROL <= R 4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-5622 HIGH
B&R APROL <4.2.07P3, <4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-20478 MEDIUM
Cisco APIC/Cloud Network Controller - Code Injection
CVSS 6.5
CVE-2024-36398 HIGH
SINEC NMS <V3.0 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 341
Exploit Likelihood Medium