Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-03-05 CVE-2020-6971 Improper Privilege Management vulnerability in Emerson Valvelink 12.0.264/13.4.118
In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.
local
low complexity
emerson CWE-269
4.6
2020-03-05 CVE-2020-5957 Improper Privilege Management vulnerability in Nvidia Geforce Experience, Quadro Firmware and Tesla Firmware
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.
local
low complexity
nvidia CWE-269
4.6
2020-03-05 CVE-2020-4278 Improper Privilege Management vulnerability in IBM products
IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges due to weak file permissions when specific debug settings are enabled in a Linux or Unix enviornment.
local
low complexity
ibm CWE-269
4.6
2020-03-02 CVE-2019-12183 Improper Privilege Management vulnerability in Safescan products
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.
network
low complexity
safescan CWE-269
5.0
2020-03-02 CVE-2020-9540 Improper Privilege Management vulnerability in Sophos Hitmanpro.Alert 3.7.6.744
Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.
local
low complexity
sophos CWE-269
4.6
2020-02-28 CVE-2020-1844 Improper Privilege Management vulnerability in Huawei Pcmanager 10.0.1.36/9.0.1.50/9.1.3.1
PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products.
local
low complexity
huawei CWE-269
4.6
2020-02-20 CVE-2020-6968 Improper Privilege Management vulnerability in Honeywell Inncom Inncontrol Firmware 3.0/3.21
Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuration files.
local
low complexity
honeywell CWE-269
4.6
2020-02-19 CVE-2020-3112 Improper Privilege Management vulnerability in Cisco Data Center Network Manager
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privileges on the application.
network
low complexity
cisco CWE-269
6.5
2020-02-19 CVE-2020-4230 Improper Privilege Management vulnerability in IBM DB2 11.1/11.5
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands.
local
low complexity
ibm CWE-269
4.6
2020-02-18 CVE-2013-6295 Improper Privilege Management vulnerability in Prestashop 1.5.5.0
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
network
low complexity
prestashop CWE-269
7.5