CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 114 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20413 | Med | 0.44 | 6.7 | 0.00 | Aug 28, 2024 | A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to insufficient security restrictions when executing… | ||
| CVE-2024-32656 | Hig | 0.44 | 7.8 | 0.00 | Apr 22, 2024 | Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability… | ||
| CVE-2024-20032 | Med | 0.44 | 6.7 | 0.00 | Mar 4, 2024 | In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08487630; Issue ID: MSV-1020. | ||
| CVE-2023-6840 | Med | 0.44 | 6.7 | 0.01 | Feb 7, 2024 | An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR. | ||
| CVE-2023-5056 | Med | 0.44 | 6.8 | 0.00 | Dec 18, 2023 | A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of… | ||
| CVE-2023-32855 | Med | 0.44 | 6.7 | 0.00 | Dec 4, 2023 | In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204. | ||
| CVE-2023-42655 | Med | 0.44 | 6.7 | 0.00 | Nov 1, 2023 | In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed | ||
| CVE-2023-40654 | Med | 0.44 | 6.7 | 0.00 | Oct 8, 2023 | In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed | ||
| CVE-2023-40653 | Med | 0.44 | 6.7 | 0.00 | Oct 8, 2023 | In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed | ||
| CVE-2023-21244 | Med | 0.44 | 6.7 | 0.00 | Oct 6, 2023 | In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21140 | Med | 0.44 | 6.8 | 0.00 | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution… | ||
| CVE-2023-21134 | Med | 0.44 | 6.8 | 0.00 | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution… | ||
| CVE-2023-21133 | Med | 0.44 | 6.8 | 0.00 | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution… | ||
| CVE-2023-21132 | Med | 0.44 | 6.8 | 0.00 | Aug 14, 2023 | In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution… | ||
| CVE-2023-20772 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441796; Issue ID: ALPS07441796. | ||
| CVE-2023-20926 | Med | 0.44 | 6.8 | 0.00 | Mar 24, 2023 | In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional… | ||
| CVE-2022-47462 | Med | 0.44 | 6.7 | 0.00 | Mar 10, 2023 | In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | ||
| CVE-2022-47461 | Med | 0.44 | 6.7 | 0.00 | Mar 10, 2023 | In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | ||
| CVE-2022-47341 | Med | 0.44 | 6.7 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. | ||
| CVE-2022-47339 | Med | 0.44 | 6.7 | 0.00 | Feb 12, 2023 | In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed. |
- risk 0.44cvss 6.7epss 0.00
A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to insufficient security restrictions when executing…
- risk 0.44cvss 7.8epss 0.00
Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability…
- risk 0.44cvss 6.7epss 0.00
In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08487630; Issue ID: MSV-1020.
- risk 0.44cvss 6.7epss 0.01
An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.
- risk 0.44cvss 6.8epss 0.00
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of…
- risk 0.44cvss 6.7epss 0.00
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
- risk 0.44cvss 6.7epss 0.00
In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed
- risk 0.44cvss 6.7epss 0.00
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed
- risk 0.44cvss 6.7epss 0.00
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed
- risk 0.44cvss 6.7epss 0.00
In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
- risk 0.44cvss 6.8epss 0.00
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…
- risk 0.44cvss 6.8epss 0.00
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…
- risk 0.44cvss 6.8epss 0.00
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…
- risk 0.44cvss 6.8epss 0.00
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…
- risk 0.44cvss 6.7epss 0.00
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441796; Issue ID: ALPS07441796.
- risk 0.44cvss 6.8epss 0.00
In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional…
- risk 0.44cvss 6.7epss 0.00
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed.