Fallos del tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2021-22817A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leadinEPSS 0.2%CVE-2023-35183HIGHSolarWinds Access Rights Manager Incorrect Default Permissions Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-42598HIGHMultiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a lEPSS 0.2%CVE-2024-12903HIGHIncorrect default permissions in Biamp Evoko HomeEPSS 0.2%CVE-2025-2502HIGHAn improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.EPSS 0.2%CVE-2026-53657HIGHLima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socketEPSS 0.2%CVE-2024-11872HIGHEpic Games Launcher Incorrect Default Permissions Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-58356LOWSurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITEEPSS 0.2%CVE-2025-54085MEDIUMElevation of privilege vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56EPSS 0.2%CVE-2023-45896HIGHntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a LiEPSS 0.2%CVE-2024-39544MEDIUMJunos OS Evolved: Low privileged local user able to view NETCONF traceoptions filesEPSS 0.2%CVE-2021-3451MEDIUMA denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to bEPSS 0.2%CVE-2023-4706HIGH A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user accoEPSS 0.2%CVE-2024-43791HIGHRequestStore has Incorrect Default PermissionsEPSS 0.2%CVE-2025-5963MEDIUMTCC Bypass via Dylib Injection in PostboxEPSS 0.2%CVE-2022-42464MEDIUMKernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in furth ...EPSS 0.2%CVE-2023-24460HIGHIncorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially EPSS 0.2%CVE-2022-4569HIGHA local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with loEPSS 0.2%CVE-2025-43350LOWA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to EPSS 0.2%CVE-2024-0245MEDIUMTask Hijacking in hamza417/inureEPSS 0.2%