CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,510 vulnerabilities with CWE-276
CVE-2025-58713 MEDIUM
Rhpam: privilege escalation via excessive /etc/passwd permissions
CVSS 6.4
CVE-2025-57854 MEDIUM
Osus-operator: privilege escalation via excessive /etc/passwd permissions
CVSS 6.4
CVE-2025-57853 MEDIUM
Web-terminal: privilege escalation via excessive /etc/passwd permissions
CVSS 6.4
CVE-2025-57851 MEDIUM
Mce: privilege escalation via excessive /etc/passwd permissions
CVSS 6.4
CVE-2025-57847 MEDIUM
Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
CVSS 6.4
CVE-2025-7024 HIGH
Local privilege escalation in Windows Server OS through installed Tetra Connectivity Server (TCS)
CVSS 7.3
CVE-2025-15615 MEDIUM
Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service
CVSS 5.8
CVE-2025-8766 MEDIUM
Noobaa-core: excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container
CVSS 6.4
CVE-2025-57849 MEDIUM
Fuse: privilege escalation via excessive /etc/passwd permissions
CVSS 6.4
CVE-2025-1789 HIGH
Genetec Update Service - Privilege Escalation
CVSS 7.8
CVE-2025-36522 MEDIUM
Intel(R) Chipset Software <10.1.20266.8668 - Privilege Escalation
CVSS 6.7
CVE-2025-36511 MEDIUM
Intel(R) Memory and Storage Tool <2.5.2 - Privilege Escalation
CVSS 6.7
CVE-2025-32453 MEDIUM
Intel(R) Graphics Driver - Privilege Escalation
CVSS 6.7
CVE-2025-31655 MEDIUM
Intel(R) Battery Life Diagnostic Tool - Privilege Escalation
CVSS 6.7
CVE-2025-22849 MEDIUM
Intel(R) Optane(TM) PMem management <CR_MGMT_01.00.00.3584, CR_MGMT...
CVSS 6.7
CVE-2025-15343 MEDIUM
Tanium Enforce 2.7.0-2.7.366 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15341 MEDIUM
Tanium Benchmark 2.7.0-2.7.98 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15340 MEDIUM
Tanium Comply 2.24.0-2.24.158 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15339 MEDIUM
Tanium Discover 4.10.0-4.10.117 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15338 MEDIUM
Tanium Partner Integration 1.0.0-1.0.223 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15337 MEDIUM
Tanium Patch 3.17.0-3.17.2299 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15336 MEDIUM
Tanium Performance 1.17.0-1.17.133 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15335 MEDIUM
Tanium Threat Response 4.5.0-4.5.265 - Information Disclosure via Incorrect Default Permissions
CVSS 4.3
CVE-2025-15334 MEDIUM
Tanium Threat Response 4.5.0-4.5.265 - Information Disclosure via Incorrect Default Permissions
CVSS 4.3
CVE-2025-15333 MEDIUM
Tanium Threat Response 4.5.0-4.5.265 - Information Disclosure via Incorrect Default Permissions
CVSS 4.3
Details
Vulnerabilities 1,510
Exploit Likelihood Medium