52 vulnerabilities classified as CWE-275 (Permission Issues). AI Chinese analysis included.
This page serves as a comprehensive aggregation resource for vulnerabilities classified under the Common Weakness Enumeration type CWE-275, which is formally defined as the Incorrect Default Permission. The content compiled here encompasses a wide variety of security flaws where software, hardware, or system configurations fail to set appropriate access controls on files, directories, or services during installation or initialization. The data covers vulnerability reports and security advisories spanning from early 2018 through mid-2024, providing a substantial historical perspective on how this weakness has manifested across different technology stacks. By navigating this collection, you can effectively track a specific vendor’s response patterns and advisory timelines regarding default permission misconfigurations, thereby gaining insight into their overall security maturity. Furthermore, the page allows for a deeper understanding of the CWE-275 weakness class by illustrating common patterns, such as open file permissions in web servers or writable directories in application frameworks, which often lead to privilege escalation or data leakage. Users can also look up a particular product’s vulnerability history to assess its long-standing exposure to this specific risk category. This structured approach facilitates better risk assessment and helps security professionals identify systemic issues rather than isolated incidents. The aggregation enables comparative analysis across multiple platforms, highlighting industry-wide trends in how developers handle initial security settings. Ultimately, this resource supports informed decision-making for patch prioritization and architectural improvements by presenting a unified view of permission-related defects. It aims to reduce the noise of scattered reports by organizing them according to their fundamental weakness type.
Vulnerabilities classified as CWE-275 (Permission Issues) represent 52 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.