Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-08-26 CVE-2020-3484 Incorrect Default Permissions vulnerability in Cisco Vision Dynamic Signage Director 6.2(0)
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to view potentially sensitive information on an affected device.
network
low complexity
cisco CWE-276
5.3
2020-08-26 CVE-2020-3152 Incorrect Default Permissions vulnerability in Cisco Connected Mobile Experiences 10.6.0/10.6.1/10.6.2
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-276
6.7
2020-08-25 CVE-2020-7824 Incorrect Default Permissions vulnerability in Ericssonlg Ipecs
A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission.
network
low complexity
ericssonlg CWE-276
6.5
2020-08-17 CVE-2020-1571 Incorrect Default Permissions vulnerability in Microsoft Windows 10
An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticated attacker could run arbitrary code with elevated system privileges.
local
low complexity
microsoft CWE-276
7.3
2020-08-14 CVE-2020-15145 Incorrect Default Permissions vulnerability in Getcomposer Composer-Setup
In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios.
local
low complexity
getcomposer CWE-276
8.2
2020-08-13 CVE-2020-8763 Incorrect Default Permissions vulnerability in Intel products
Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2020-08-13 CVE-2020-8743 Incorrect Default Permissions vulnerability in Intel Mailbox Interface Driver
Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2020-08-13 CVE-2020-12287 Incorrect Default Permissions vulnerability in Intel Distribution of Openvino Toolkit
Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2020-08-08 CVE-2020-15821 Incorrect Default Permissions vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
network
low complexity
jetbrains CWE-276
6.5
2020-08-07 CVE-2020-8026 Incorrect Default Permissions vulnerability in Opensuse Backports Sle, Leap and Tumbleweed
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root.
local
low complexity
opensuse CWE-276
7.8