Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-22368 Incorrect Default Permissions vulnerability in Huawei Emui and Magic UI
There is a Permission Control Vulnerability in Huawei Smartphone.
network
low complexity
huawei CWE-276
7.5
2021-06-30 CVE-2021-22371 Incorrect Default Permissions vulnerability in Huawei Emui and Magic UI
There is an Improper Permission Management Vulnerability in Huawei Smartphone.
network
low complexity
huawei CWE-276
7.5
2021-06-29 CVE-2021-20490 Incorrect Default Permissions vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings.
local
low complexity
ibm CWE-276
5.5
2021-06-24 CVE-2021-21737 Incorrect Default Permissions vulnerability in ZTE Zxv10 B860H V5.0 Firmware V83011303.0010/V83011303.0016
A smart STB product of ZTE is impacted by a permission and access control vulnerability.
network
low complexity
zte CWE-276
7.5
2021-06-22 CVE-2021-34395 Incorrect Default Permissions vulnerability in Nvidia Jetson Linux
Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.
local
low complexity
nvidia CWE-276
4.2
2021-06-21 CVE-2021-34387 Incorrect Default Permissions vulnerability in Nvidia Jetson Linux
The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.
local
low complexity
nvidia CWE-276
6.7
2021-06-17 CVE-2021-0143 Incorrect Default Permissions vulnerability in Intel Brand Verification Tool
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2021-06-10 CVE-2021-21736 Incorrect Default Permissions vulnerability in ZTE Zxhn Hs562 Firmware 1.0.0.0B2.0000/1.0.0.0B3.0000
A smart camera product of ZTE is impacted by a permission and access control vulnerability.
network
low complexity
zte CWE-276
7.2
2021-06-10 CVE-2021-31998 Incorrect Default Permissions vulnerability in Opensuse INN 2.4.2170.21.3.1
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root.
local
low complexity
opensuse CWE-276
7.8
2021-06-09 CVE-2021-0058 Incorrect Default Permissions vulnerability in Intel Lapbc510 Firmware and Lapbc710 Firmware
Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8