CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,511 vulnerabilities with CWE-276
CVE-2023-28870 MEDIUM
NCP Secure Enterprise Client <12.22 - Info Disclosure
CVSS 6.5
CVE-2023-6273 MEDIUM
Sound Booster Module - Info Disclosure
CVSS 5.3
CVE-2023-46773 CRITICAL
Huawei EMUI and HarmonyOS - Privilege Escalation via PMS Module Permission Management
CVSS 9.8
CVE-2023-37572 HIGH
Softing OPC Suite < 5.30 - Unauthenticated Sensitive Information Exposure via OSF_discovery Service Weak Permissions
CVSS 7.5
CVE-2023-40076 MEDIUM
Android - Local Privilege Escalation via CredentialManagerUi PendingIntent Permission Bypass
CVSS 5.5
CVE-2023-21216 CRITICAL
Android - Use-After-Free in PMRChangeSparseMemOSMem
CVSS 9.8
CVE-2023-47462 CRITICAL
GL.iNet AX1800 < 3.215 - Remote Code Execution via File Sharing Function
CVSS 9.8
CVE-2023-42501 MEDIUM
Apache Superset < 2.1.2 - Authenticated Unnecessary Read Permissions in Gamma Role
CVSS 4.3
CVE-2023-6302 MEDIUM
CSZCMS 1.3.0 - Permission Issues in File Manager Page
CVSS 4.7
CVE-2023-47250 HIGH
mprivacy-tools < 2.0.406g - Authenticated X11 Desktop Access Control Bypass via DISPLAY ID
CVSS 8.8
CVE-2023-43081 MEDIUM
PowerProtect Agent for File System <19.14 - Privilege Escalation
CVSS 4.0
CVE-2023-42774 MEDIUM
OpenHarmony < 3.2.2 - Unauthenticated Information Disclosure via Incorrect Default Permissions
CVSS 6.2
CVE-2023-3116 HIGH
OpenHarmony <3.2.2 - Info Disclosure
CVSS 7.3
CVE-2023-40363 HIGH
IBM InfoSphere Information Server 11.7 - Authenticated Arbitrary File Modification via Incorrect File Permissions
CVSS 8.1
CVE-2023-48648 CRITICAL
Concrete CMS <8.5.13,9.x <9.2.2 - Info Disclosure
CVSS 9.8
CVE-2023-47335 MEDIUM
Autel Robotics EVO Nano Drone Firmware 1.6.5 - Incorrect Default Permissions in setNFZEnable Function
CVSS 6.5
CVE-2023-41718 HIGH
Ivanti Secure Access Client - Privilege Escalation via Unauthorized File Control
CVSS 7.8
CVE-2023-35080 HIGH
Ivanti Secure Access Client < 22.6 - Incorrect Default Permissions
CVSS 7.8
CVE-2023-32638 MEDIUM
Intel Arc RGB Controller < 1.06 - Authenticated Privilege Escalation via Incorrect Default Permissions
CVSS 6.7
CVE-2023-27305 MEDIUM
Intel(R) Arc(TM) Control <1.73.5335.2 - Privilege Escalation
CVSS 6.7
CVE-2023-23583 HIGH
Intel Core i3/i5/i7 10th Gen Firmware - Unauthenticated Privilege Escalation and Information Disclosure via Local Access
CVSS 8.8
CVE-2023-43902 CRITICAL
emsigner 2.8.7 - Unauthenticated Account Access via Password Reset Token
CVSS 9.8
CVE-2023-46743 HIGH
application-collabora - Info Disclosure
CVSS 7.3
CVE-2023-4706 HIGH
Lenovo Preload Directory - Privilege Escalation via Incorrect Default Permissions
CVSS 7.3
CVE-2023-43984 HIGH
Smart Soft advancedexport <4.4.7 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 1,511
Exploit Likelihood Medium