Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2024-06-27 CVE-2023-38370 Incorrect Default Permissions vulnerability in IBM Security Access Manager 10.0.0.0/10.0.7.1
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages.
network
low complexity
ibm CWE-276
6.5
2024-06-14 CVE-2024-34012 Incorrect Default Permissions vulnerability in Acronis Cloud Manager
Local privilege escalation due to insecure folder permissions.
local
low complexity
acronis CWE-276
4.4
2024-06-12 CVE-2024-37038 Incorrect Default Permissions vulnerability in Schneider-Electric Sage RTU Firmware
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
network
low complexity
schneider-electric CWE-276
8.8
2024-02-14 CVE-2023-41231 Incorrect Default Permissions vulnerability in Intel Assistive Context-Aware Toolkit
Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2024-02-14 CVE-2023-34315 Incorrect Default Permissions vulnerability in Intel Virtual Raid on CPU 8.0.0.4035
Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2024-02-13 CVE-2023-38960 Incorrect Default Permissions vulnerability in Raidenftpd 2.4.4005
Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.
local
low complexity
raidenftpd CWE-276
7.3
2024-02-13 CVE-2023-50236 Incorrect Default Permissions vulnerability in Siemens Polarion ALM 21.0/2304.0
A vulnerability has been identified in Polarion ALM (All versions < V2404.0).
local
low complexity
siemens CWE-276
7.8
2024-02-01 CVE-2024-22430 Incorrect Default Permissions vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability.
local
low complexity
dell CWE-276
5.5
2024-01-30 CVE-2024-21840 Incorrect Default Permissions vulnerability in Hitachi Storage Plug-In 04.8.0/04.9.0
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.
local
low complexity
hitachi CWE-276
7.1
2024-01-26 CVE-2023-29081 Incorrect Default Permissions vulnerability in Flexera Installshield
A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2.
local
low complexity
flexera CWE-276
5.5