Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2023-10-11 CVE-2023-38817 Improper Privilege Management vulnerability in Echo Anti Cheat Tool
An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component.
local
low complexity
echo CWE-269
7.8
2023-10-11 CVE-2023-43960 Improper Privilege Management vulnerability in Dlink Dph-400Se Firmware 2.2.15.8
An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.
network
low complexity
dlink CWE-269
8.8
2023-10-11 CVE-2023-44105 Improper Privilege Management vulnerability in Huawei Emui and Harmonyos
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-269
critical
9.8
2023-10-06 CVE-2023-5214 Improper Privilege Management vulnerability in Puppet Bolt
In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.
network
low complexity
puppet CWE-269
critical
9.8
2023-10-04 CVE-2023-20235 Improper Privilege Management vulnerability in Cisco IOS XE
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application development mode.
network
low complexity
cisco CWE-269
8.8
2023-09-28 CVE-2023-40375 Improper Privilege Management vulnerability in IBM I
Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability.
local
low complexity
ibm CWE-269
7.8
2023-09-27 CVE-2023-34043 Improper Privilege Management vulnerability in VMWare Aria Operations and Cloud Foundation
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
local
low complexity
vmware CWE-269
6.7
2023-09-27 CVE-2023-39375 Improper Privilege Management vulnerability in Siberiancms
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
network
low complexity
siberiancms CWE-269
critical
9.8
2023-09-15 CVE-2023-36657 Improper Privilege Management vulnerability in Opswat Metadefender Kiosk
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996.
network
low complexity
opswat CWE-269
critical
9.8
2023-09-07 CVE-2023-20193 Improper Privilege Management vulnerability in Cisco Identity Services Engine
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root.
local
low complexity
cisco CWE-269
6.7