Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2021-1371 Improper Privilege Management vulnerability in Cisco IOS XE Sd-Wan 17.2.0
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration.
low complexity
cisco CWE-269
6.6
2021-03-17 CVE-2020-11228 Improper Privilege Management vulnerability in Qualcomm products
Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-269
4.6
2021-03-17 CVE-2017-20002 Improper Privilege Management vulnerability in Debian Linux and Shadow
The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty.
local
low complexity
debian CWE-269
4.6
2021-03-15 CVE-2020-4184 Improper Privilege Management vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
network
low complexity
ibm CWE-269
7.5
2021-03-11 CVE-2021-27077 Improper Privilege Management vulnerability in Microsoft products
Windows Win32k Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-03-11 CVE-2021-26863 Improper Privilege Management vulnerability in Microsoft products
Windows Win32k Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-269
7.0
2021-03-11 CVE-2021-24095 Improper Privilege Management vulnerability in Microsoft products
DirectX Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-269
7.0
2021-03-11 CVE-2021-24090 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2016
Windows Error Reporting Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-03-11 CVE-2021-1729 Improper Privilege Management vulnerability in Microsoft products
Windows Update Stack Setup Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.1
2021-03-11 CVE-2021-1640 Improper Privilege Management vulnerability in Microsoft products
Windows Print Spooler Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8