CWE-281— Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.— MITRE CWE catalog
360 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-281page 2 of 8
- CVE-2020-0265MEDIUMCVSS 5.5EG 5.52020-09-18
In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod…
- CVE-2020-0269MEDIUMCVSS 5.5EG 5.52020-09-18
In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…
- CVE-2020-0327MEDIUMCVSS 5.5EG 5.52020-09-18
In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: …
- CVE-2020-0331MEDIUMCVSS 5.5EG 5.52020-09-18
In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr…
- CVE-2020-0405HIGHCVSS 7.8EG 7.82020-09-18
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2020-10083CRITICALCVSS 9.1EG 9.12020-03-13
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
- CVE-2020-12330HIGHCVSS 7.8EG 7.82020-11-12
Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12332HIGHCVSS 7.8EG 7.82020-11-12
Improper permissions in the installer for the Intel(R) HID Event Filter Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12334HIGHCVSS 7.8EG 7.82020-11-12
Improper permissions in the installer for the Intel(R) Advisor tools before version 2020 Update 2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12335HIGHCVSS 7.8EG 7.82020-11-12
Improper permissions in the installer for the Intel(R) Processor Identification Utility before version 6.4.0603 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12345HIGHCVSS 7.8EG 7.82020-11-12
Improper permissions in the installer for the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12353MEDIUMCVSS 6.5EG 6.52020-11-12
Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access.
- CVE-2020-12744HIGHCVSS 7.8EG 7.82022-10-20
The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.
- CVE-2020-13230MEDIUMCVSS 4.3EG 4.32020-05-20
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
- CVE-2020-13282LOWCVSS 3.1EG 3.12020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
- CVE-2020-13308LOWCVSS 2.7EG 2.72020-09-15
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication …
- CVE-2020-13763HIGHCVSS 7.5EG 7.52020-06-02
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
- CVE-2020-14958MEDIUMCVSS 6.5EG 6.52020-06-21
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
- CVE-2020-15113MEDIUMCVSS 5.7EG 5.72020-08-05
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted a…
- CVE-2020-15496HIGHCVSS 7.8EG 7.82021-07-15
Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
- CVE-2020-16910MEDIUMCVSS 6.2EG 6.22020-10-16
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>…
- CVE-2020-18329HIGHCVSS 7.5EG 7.52023-01-26
An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticated access to the configuration and service interface.
- CVE-2020-18890CRITICALCVSS 9.8EG 9.82021-05-06
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
- CVE-2020-2025HIGHCVSS 8.8EG 8.82020-05-19
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers…
- CVE-2020-24525HIGHCVSS 7.8EG 7.82020-11-12
Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-26246HIGHCVSS 7.7EG 7.72020-12-03
Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.
- CVE-2020-27383HIGHCVSS 7.8EG 7.82021-06-09
Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to…
- CVE-2020-36070CRITICALCVSS 9.8EG 9.82023-04-26
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
- CVE-2020-5796HIGHCVSS 7.8EG 7.82020-11-13
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with roo…
- CVE-2020-6564MEDIUMCVSS 6.5EG 6.52020-09-21
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
- CVE-2020-7063MEDIUMCVSS 5.5EG 5.52020-02-27
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original …
- CVE-2020-8117MEDIUMCVSS 4.3EG 4.32020-02-04
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
- CVE-2020-8182HIGHCVSS 8.0EG 8.02020-10-05
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
- CVE-2020-8190HIGHCVSS 7.5EG 7.52020-07-10
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
- CVE-2020-8633MEDIUMCVSS 5.3EG 5.32020-02-18
An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar stayed mounted and accessible.
- CVE-2020-8634HIGHCVSS 7.8EG 7.82020-03-07
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive s…
- CVE-2020-8913HIGHCVSS 8.8EG 8.82020-08-12
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a vict…
- CVE-2020-9442HIGHCVSS 7.8EG 7.82020-02-28
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.
- CVE-2020-9781MEDIUMCVSS 5.3EG 5.32020-04-01
The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.
- CVE-2021-0064HIGHCVSS 7.8EG 7.82021-11-17
Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0074HIGHCVSS 7.8EG 7.82021-06-09
Improper permissions in the installer for the Intel(R) Computing Improvement Program software before version 2.4.5982 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0077HIGHCVSS 7.8EG 7.82021-06-09
Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0542MEDIUMCVSS 5.5EG 5.52021-06-22
In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is neede…
- CVE-2021-0653MEDIUMCVSS 5.5EG 5.52021-12-15
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileg…
- CVE-2021-0704MEDIUMCVSS 5.5EG 5.52021-12-15
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local inform…
- CVE-2021-0927HIGHCVSS 7.8EG 7.82021-12-15
In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2021-0953HIGHCVSS 7.8EG 7.82021-12-15
In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execut…
- CVE-2021-0965HIGHCVSS 8.8EG 8.82021-12-15
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed…
- CVE-2021-0985HIGHCVSS 7.8EG 7.82021-12-15
In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…
- CVE-2021-0999HIGHCVSS 7.8EG 7.82021-12-15
In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permission check. This could lead to local escalation of privilege with no additional execution …
Map vulnerabilities like CWE-281 to your infrastructure
EchelonGraph correlates every CVE — across CWE-281 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →