Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-10-19 CVE-2020-9112 Improper Privilege Management vulnerability in Huawei Taurus-An00B Firmware 10.1.0.156
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability.
local
low complexity
huawei CWE-269
7.8
2020-10-15 CVE-2020-7334 Improper Privilege Management vulnerability in Mcafee Application and Change Control
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer.
local
low complexity
mcafee CWE-269
8.2
2020-10-14 CVE-2020-7330 Improper Privilege Management vulnerability in Mcafee Total Protection 4.0.161.1
Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call malicious software to execute with elevated privileges via editing of environment variables
local
low complexity
mcafee CWE-269
8.8
2020-10-07 CVE-2020-26880 Improper Privilege Management vulnerability in multiple products
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
local
low complexity
sympa fedoraproject debian CWE-269
7.8
2020-10-07 CVE-2020-26596 Improper Privilege Management vulnerability in Elementor PRO 3.0.5
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet.
network
low complexity
elementor CWE-269
8.8
2020-10-05 CVE-2020-8223 Improper Privilege Management vulnerability in multiple products
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
network
low complexity
nextcloud fedoraproject CWE-269
6.5
2020-09-24 CVE-2020-3396 Improper Privilege Management vulnerability in Cisco IOS XE 16.12.1
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections.
low complexity
cisco CWE-269
7.2
2020-09-24 CVE-2015-4719 Improper Privilege Management vulnerability in Pexip Infinity 7.0/9
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
network
low complexity
pexip CWE-269
critical
9.8
2020-09-23 CVE-2020-25595 Improper Privilege Management vulnerability in multiple products
An issue was discovered in Xen through 4.14.x.
local
low complexity
xen fedoraproject debian opensuse CWE-269
7.8
2020-09-18 CVE-2020-8247 Improper Privilege Management vulnerability in Citrix products
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.
network
low complexity
citrix CWE-269
8.8