Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2023-11-13 CVE-2023-47801 Incorrect Permission Assignment for Critical Resource vulnerability in Clickstudios Passwordstate 9.5/9.6/9.7
An issue was discovered in Click Studios Passwordstate before 9811.
network
low complexity
clickstudios CWE-732
4.7
2023-11-12 CVE-2023-28134 Incorrect Permission Assignment for Critical Resource vulnerability in Checkpoint Endpoint Security E84/E85/E86
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security.
local
low complexity
checkpoint CWE-732
7.8
2023-11-08 CVE-2023-3282 Incorrect Permission Assignment for Critical Resource vulnerability in Paloaltonetworks Cortex Xsoar
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.
local
low complexity
paloaltonetworks CWE-732
6.7
2023-11-08 CVE-2023-5136 Incorrect Permission Assignment for Critical Resource vulnerability in NI products
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure.
local
low complexity
ni CWE-732
5.5
2023-10-26 CVE-2023-46449 Incorrect Permission Assignment for Critical Resource vulnerability in Mayurik Inventory Management System 1.0
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control.
network
low complexity
mayurik CWE-732
8.8
2023-10-25 CVE-2023-42861 Incorrect Permission Assignment for Critical Resource vulnerability in Apple Macos 14.0
A logic issue was addressed with improved state management.
network
low complexity
apple CWE-732
6.5
2023-10-25 CVE-2023-42489 Incorrect Permission Assignment for Critical Resource vulnerability in Busbaer Eisbaer Scada 3.0.6433.1964
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
network
low complexity
busbaer CWE-732
critical
9.8
2023-10-20 CVE-2023-40361 Incorrect Permission Assignment for Critical Resource vulnerability in Secudos Qiata 4.13
SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob.
local
low complexity
secudos CWE-732
7.8
2023-10-19 CVE-2023-34437 Incorrect Permission Assignment for Critical Resource vulnerability in Bakerhughes Bentley Nevada 3500 System Firmware 5.0.5
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
network
low complexity
bakerhughes CWE-732
7.5
2023-10-13 CVE-2023-44201 Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Junos
An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker to read configuration changes without having the permissions. When a user with the respective permissions commits a configuration change, a specific file is created.
local
low complexity
juniper CWE-732
5.5