Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-275 (Permission Issues) — Vulnerability Class 52

52 vulnerabilities classified as CWE-275 (Permission Issues). AI Chinese analysis included.

This page serves as a comprehensive aggregation resource for vulnerabilities classified under the Common Weakness Enumeration type CWE-275, which is formally defined as the Incorrect Default Permission. The content compiled here encompasses a wide variety of security flaws where software, hardware, or system configurations fail to set appropriate access controls on files, directories, or services during installation or initialization. The data covers vulnerability reports and security advisories spanning from early 2018 through mid-2024, providing a substantial historical perspective on how this weakness has manifested across different technology stacks. By navigating this collection, you can effectively track a specific vendor’s response patterns and advisory timelines regarding default permission misconfigurations, thereby gaining insight into their overall security maturity. Furthermore, the page allows for a deeper understanding of the CWE-275 weakness class by illustrating common patterns, such as open file permissions in web servers or writable directories in application frameworks, which often lead to privilege escalation or data leakage. Users can also look up a particular product’s vulnerability history to assess its long-standing exposure to this specific risk category. This structured approach facilitates better risk assessment and helps security professionals identify systemic issues rather than isolated incidents. The aggregation enables comparative analysis across multiple platforms, highlighting industry-wide trends in how developers handle initial security settings. Ultimately, this resource supports informed decision-making for patch prioritization and architectural improvements by presenting a unified view of permission-related defects. It aims to reduce the noise of scattered reports by organizing them according to their fundamental weakness type.

CVE ID Title CVSS Severity Published
CVE-2022-0343 Local Priviledge escalation in Perfetto Dev scripts — Perfetto Dev Scripts 3.3 Low 2022-03-29
CVE-2022-0742 Memory leak in ICMP6 in Linux Kernel — Kernel 9.1 Critical 2022-03-18
CVE-2021-22571 Information Leak in SA360-webquery-bigquery through read on /tmp — google/sa360-webquery-bigquery 5.5 Medium 2022-03-18
CVE-2021-32006 GateManager information leak for LinkManager Users — GateManager 5.0 Medium 2022-03-07
CVE-2021-22566 Incorrect mapping of Executable bits in Fuchsia Kernel — Fuchsia 8.8 - 2022-01-18
CVE-2022-22988 Insecure file and directory permissions on EdgeRover — EdgeRover 7.7 High 2022-01-13
CVE-2021-1437 Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability — Cisco Aironet Access Point Software 7.5 High 2021-03-24
CVE-2020-6022 Check Point ZoneAlarm 授权问题漏洞 — Check Point ZoneAlarm 5.5 - 2020-10-27
CVE-2020-3152 Cisco Connected Mobile Experiences Privilege Escalation Vulnerability — Cisco Connected Mobile Experiences 6.7 - 2020-08-26
CVE-2014-1422 Location service uses cached authorization even after revocation — trust-store (Ubuntu) 5.0 Medium 2020-07-22
CVE-2020-8471 ABB Central Licensing System - Weak File Permissions — Central Licensing System 7.8 High 2020-04-29
CVE-2020-8474 ABB System 800xA Weak Registry Permissions — System 800xA Base 7.8 High 2020-04-22
CVE-2019-15962 Cisco TelePresence Collaboration Endpoint Software Arbitrary File Write Vulnerability — Cisco TelePresence TC Software 4.4 - 2019-10-16
CVE-2019-12622 Cisco RoomOS Software Privilege Escalation Vulnerability — Cisco TelePresence CE Software 7.1 - 2019-08-21
CVE-2019-1618 Cisco Nexus 9000 Series Switches Standalone NX-OS Mode Tetration Analytics Agent Arbitrary Code Execution Vulnerability — Nexus 9000 Series Switches in Standalone NX-OS Mode 7.8 - 2019-03-11
CVE-2018-0449 Cisco Jabber Client Framework Insecure Directory Permissions Vulnerability — Cisco Jabber for Mac 4.2 - 2019-01-10
CVE-2018-15379 Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability — Cisco Prime Infrastructure 9.8 - 2018-10-05
CVE-2018-0392 Cisco Policy Suite 安全漏洞 — Cisco Policy Suite unknown 5.5 - 2018-07-18
CVE-2017-0884 Nextcloud Server 安全漏洞 — Nextcloud Server 4.3 - 2017-04-05
CVE-2017-0883 Nextcloud Server 安全漏洞 — Nextcloud Server 5.4 - 2017-04-05
CVE-2016-9462 ownCloud Server和Nextcloud Server 安全漏洞 — Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 4.3 - 2017-03-28
CVE-2016-9461 Nextcloud Server和ownCloud Server 安全漏洞 — Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 4.3 - 2017-03-28

Vulnerabilities classified as CWE-275 (Permission Issues) represent 52 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.