Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-20254 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Sd-Wan Manager
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance.
network
low complexity
cisco CWE-732
8.8
2023-09-27 CVE-2023-4565 Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Emui and Harmonyos
Broadcast permission control vulnerability in the framework module.
network
low complexity
huawei CWE-732
5.3
2023-09-25 CVE-2023-41295 Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Emui and Harmonyos
Vulnerability of improper permission management in the displayengine module.
network
low complexity
huawei CWE-732
5.3
2023-09-12 CVE-2023-32005 Incorrect Permission Assignment for Critical Resource vulnerability in Nodejs Node.Js
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file stats through the `fs.statfs` API.
network
low complexity
nodejs CWE-732
5.3
2023-09-08 CVE-2023-4777 Incorrect Permission Assignment for Critical Resource vulnerability in Qualys Container Scanning Connector 1.6.2.6
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins. 
network
low complexity
qualys CWE-732
4.3
2023-09-01 CVE-2023-3915 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1.
network
low complexity
gitlab CWE-732
7.2
2023-08-31 CVE-2023-34391 Incorrect Permission Assignment for Critical Resource vulnerability in Selinc Sel-5033 Acselerator Real-Time Automation Controller
Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more details. This issue affects SEL-5033 AcSELerator RTAC Software: before 1.35.151.21000.
local
low complexity
selinc CWE-732
5.5
2023-08-28 CVE-2023-40754 Incorrect Permission Assignment for Critical Resource vulnerability in PHPjabbers CAR Rental Script 3.0
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-732
8.8
2023-08-24 CVE-2023-4228 Incorrect Permission Assignment for Critical Resource vulnerability in Moxa Iologik E4200 Firmware 1.6
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application.
network
low complexity
moxa CWE-732
4.3
2023-08-23 CVE-2023-20200 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco products
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the improper handling of specific SNMP requests.
network
high complexity
cisco CWE-732
6.3