Skip to main content

Threats Tagged 'cwe-272'

View all threats tagged with 'cwe-272'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-272

Threats Tagged 'cwe-272'

Click on any threat for detailed analysis and mitigation recommendations

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

Join the discussion

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

Join the discussion

CVE-2025-62299 is a least privilege violation vulnerability in HCL IntelliOps Event Management (IEM) version 1.4.0. This flaw allows an attacker with certain privileges to access resources with elevated privileges that they should not normally have. The vulnerability has a medium severity rating with a CVSS score of 6.6.

Join the discussion

Dell Alienware Command Center (AWCC) versions prior to 6.14.20.0 have a least privilege violation vulnerability (CWE-272) that allows a low privileged local attacker to potentially elevate their privileges. This vulnerability is rated high severity with a CVSS score of 7.3. No official patch or remediation details are provided in the input data.

Join the discussion

Dell Alienware Command Center (AWCC) versions prior to 6.14.20.0 have a vulnerability involving improper link resolution before file access. This flaw allows a low privileged local attacker to exploit link following issues, potentially causing denial of service and elevation of privileges. The vulnerability is classified under CWE-272 (Least Privilege Violation).

Join the discussion

CVE-2026-39459 is a high-severity vulnerability in F5 BIG-IP affecting iControl REST and TMOS Shell (tmsh). It allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects that enable running arbitrary commands. This violates the principle of least privilege and could lead to full system compromise. The affected versions include 16.1.0, 17.1.0, 17.5.0, and 21.

Join the discussion

Dell Alienware Command Center (AWCC) versions prior to 6.13.8.0 contain a least privilege violation vulnerability (CWE-272) that allows a low privileged local attacker to potentially elevate their privileges. The vulnerability has a CVSS v3.1 score of 5.3, indicating a medium severity level. There is no vendor advisory or patch information currently available, and no known exploits in the wild have been reported. The vulnerability requires local access and high attack complexity, with no user interaction needed. Confidentiality is not impacted, but integrity and availability impacts are rated high and low respectively.

Join the discussion
0

The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. Security Fix(es): * sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.

Join the discussion

CVE-2025-59106 is a high-severity vulnerability in dormakaba Access Manager 92xx-k7 versions prior to BAME 06.00. The core issue is that the binary responsible for the web server and executing all actions from the Web UI runs with root privileges, violating the least privilege principle (CWE-272). This design flaw allows an attacker who has already gained code execution on the system via other vulnerabilities to escalate privileges to root, enabling full control over the device. The vulnerability has a CVSS score of 8.8, indicating high impact on confidentiality, integrity, and availability without requiring user interaction. Although no known exploits are currently in the wild, the risk is significant due to the ease of privilege escalation once initial access is obtained. European organizations using dormakaba Access Manager 92xx-k7 should prioritize patching and implement compensating controls to limit exposure. Countries with high adoption of dormakaba physical access control systems and critical infrastructure relying on them are at greater risk.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Tag: cwe-272
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses