Fallos del tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2025-57847MEDIUMAnsible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissionsEPSS 0.2%CVE-2023-44194HIGHJunos OS: An unauthenticated attacker with local access to the device can create a backdoor with root privilegesEPSS 0.2%CVE-2023-34315MEDIUMIncorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2024-55957HIGHIn Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver pacEPSS 0.2%CVE-2025-8069HIGHLocal Privilege Escalation Vulnerability in AWS Client VPN Windows ClientEPSS 0.2%CVE-2023-28739MEDIUMIncorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potEPSS 0.2%CVE-2023-32638MEDIUMIncorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially eEPSS 0.2%CVE-2023-27305MEDIUMIncorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentEPSS 0.2%CVE-2023-40154MEDIUMIncorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enEPSS 0.2%CVE-2023-41231MEDIUMIncorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentialEPSS 0.2%CVE-2025-0542HIGHG DATA Management Server Local privilege escalationEPSS 0.2%CVE-2024-53921LOWAn issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permisEPSS 0.2%CVE-2022-48685HIGHAn issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is execEPSS 0.2%CVE-2025-23347HIGHNVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulneEPSS 0.2%CVE-2023-30905The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege.EPSS 0.2%CVE-2025-15523MEDIUMTCC Bypass via Inherited Permissions in Bundled Interpreter in Inkscape.appEPSS 0.2%CVE-2024-3904HIGHIncorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions EPSS 0.2%CVE-2025-8766MEDIUMNoobaa-core: excessive permissions of /etc could lead to escalation of privilege in the noobaa-core containerEPSS 0.2%CVE-2024-4763HIGHAn insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) thEPSS 0.2%CVE-2023-28966HIGHJunos OS Evolved: Local low-privileged user with shell access can execute CLI commands as rootEPSS 0.2%