Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local atta
extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Blu
Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escal
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc
Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achiev
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve pr
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve
In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local
Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SG
An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple devi
On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writ
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS S
ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a files
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessP
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may a
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be
By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could exp
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeV
Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop
Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authe
Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user t
Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged us
Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticat
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass S
Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authentica
Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A
Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an au
Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based
An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the refe
Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 ma
Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1
Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authen
Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially en
Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user t
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must hav
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow
Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may
Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authe
Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user
In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server componen
pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written t
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that g
Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecu
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/e
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started