Fallos del tipo CWE-732

792 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2022-39186MEDIUMEXFO - BV-10 Performance Endpoint Unit Misconfiguration EPSS 0.2%CVE-2023-28123MEDIUMA permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while EPSS 0.2%CVE-2025-24481HIGHFactoryTalk® View Site Edition - Incorrect Permission AssignmentEPSS 0.2%CVE-2026-29126HIGHWorld-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Receiver Leads To Potential LPEEPSS 0.2%CVE-2025-67246HIGHA local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handlerEPSS 0.2%CVE-2023-45205HIGHA vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific fiEPSS 0.2%CVE-2022-30527HIGHA vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific EPSS 0.2%CVE-2023-41776MEDIUMLocal Privilege Escalation Vulnerability of ZTE's ZXCLOUD iRAIEPSS 0.2%CVE-2024-31202HIGHA “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perforEPSS 0.2%CVE-2025-8886MEDIUMAuthorization Bypass in Usta Information Systems' Aybs InteraktifEPSS 0.2%CVE-2026-6386MEDIUMMissing large page handling in pmap_pkru_update_range()EPSS 0.2%CVE-2025-31262MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18EPSS 0.2%CVE-2024-24912MEDIUMLocal privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL fileEPSS 0.2%CVE-2023-33990HIGHDenial of Service (DoS) vulnerability in SAP SQL AnywhereEPSS 0.2%CVE-2025-52992LOWThe Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes tEPSS 0.2%CVE-2024-22016HIGHIncorrect Permission Assignment for Critical Resource in Rapid SCADAEPSS 0.2%CVE-2023-38557HIGHA vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the uEPSS 0.2%CVE-2026-41217HIGHBIG-IP tmsh vulnerabilityEPSS 0.2%CVE-2025-52627MEDIUMHCL AION is susceptible to Incorrect Permission Assignment for Critical ResourceEPSS 0.2%CVE-2025-23285MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful eEPSS 0.2%