Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-10-25 CVE-2022-28169 Improper Privilege Management vulnerability in Broadcom Fabric Operating System
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user.
network
low complexity
broadcom CWE-269
8.8
2022-10-21 CVE-2022-34438 Improper Privilege Management vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error.
local
low complexity
dell CWE-269
6.7
2022-10-18 CVE-2022-22239 Improper Privilege Management vulnerability in Juniper Junos OS Evolved
An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems.
local
low complexity
juniper CWE-269
8.8
2022-10-17 CVE-2022-3421 Improper Privilege Management vulnerability in Google Drive
An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user.
local
low complexity
google CWE-269
7.3
2022-10-12 CVE-2022-2249 Improper Privilege Management vulnerability in Avaya Aura Communication Manager
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges.
local
low complexity
avaya CWE-269
6.7
2022-10-06 CVE-2022-2637 Improper Privilege Management vulnerability in Hitachi Storage Plug-In 04.8.0
Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.0.
network
low complexity
hitachi CWE-269
8.8
2022-09-27 CVE-2022-41604 Improper Privilege Management vulnerability in Checkpoint Zonealarm
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.
local
low complexity
checkpoint CWE-269
8.8
2022-09-19 CVE-2022-38351 Improper Privilege Management vulnerability in Supremainc Biostar 2 2.8.16
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
network
low complexity
supremainc CWE-269
8.8
2022-09-19 CVE-2022-40142 Improper Privilege Management vulnerability in Trendmicro Apex ONE 2019
A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileges on affected installations.
local
low complexity
trendmicro CWE-269
7.8
2022-09-15 CVE-2022-36075 Improper Privilege Management vulnerability in Nextcloud Files Access Control
Nextcloud files access control is a nextcloud app to manage access control for files.
network
low complexity
nextcloud CWE-269
4.3