A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensiti
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigation
Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated atta
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWi
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compil
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs
A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for
Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access gl
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the la
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for cri
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbi
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitr
Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a
Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root own
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest
IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can cre
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated us
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attac
A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may a
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an
Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user t
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user t
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/E
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict w
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS So
A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds hav
Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits
Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If e
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivilege
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started