Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-09-09 CVE-2020-10050 Incorrect Default Permissions vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2).
local
low complexity
siemens CWE-276
7.8
2020-09-09 CVE-2020-10049 Incorrect Default Permissions vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2).
local
low complexity
siemens CWE-276
7.3
2020-09-03 CVE-2019-10679 Incorrect Default Permissions vulnerability in Thomsonreuters Eikon 4.0.42144
Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.
local
low complexity
thomsonreuters CWE-276
7.8
2020-09-01 CVE-2020-23971 Incorrect Default Permissions vulnerability in Gmapfp J3.30
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions.
network
low complexity
gmapfp CWE-276
7.5
2020-09-01 CVE-2020-24584 Incorrect Default Permissions vulnerability in multiple products
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used).
7.5
2020-09-01 CVE-2020-24583 Incorrect Default Permissions vulnerability in multiple products
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used).
7.5
2020-08-31 CVE-2020-7527 Incorrect Default Permissions vulnerability in Schneider-Electric Somove
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
local
low complexity
schneider-electric CWE-276
7.8
2020-08-31 CVE-2020-13468 Incorrect Default Permissions vulnerability in Gigadevice Gd32F130 Firmware
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
low complexity
gigadevice CWE-276
6.8
2020-08-27 CVE-2020-24717 Incorrect Default Permissions vulnerability in Openzfs
OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.
local
low complexity
openzfs CWE-276
7.8
2020-08-26 CVE-2020-3485 Incorrect Default Permissions vulnerability in Cisco Vision Dynamic Signage Director 6.2.0
A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform.
network
low complexity
cisco CWE-276
6.3