VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 114 of 464
  • CVE-2024-20413MedAug 28, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to insufficient security restrictions when executing…

  • CVE-2024-32656HigApr 22, 2024
    risk 0.44cvss 7.8epss 0.00

    Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability…

  • CVE-2024-20032MedMar 4, 2024
    risk 0.44cvss 6.7epss 0.00

    In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08487630; Issue ID: MSV-1020.

  • CVE-2023-6840MedFeb 7, 2024
    risk 0.44cvss 6.7epss 0.01

    An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

  • CVE-2023-5056MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of…

  • CVE-2023-32855MedDec 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.

  • CVE-2023-42655MedNov 1, 2023
    risk 0.44cvss 6.7epss 0.00

    In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed

  • CVE-2023-40654MedOct 8, 2023
    risk 0.44cvss 6.7epss 0.00

    In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

  • CVE-2023-40653MedOct 8, 2023
    risk 0.44cvss 6.7epss 0.00

    In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

  • CVE-2023-21244MedOct 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21140MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.00

    In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…

  • CVE-2023-21134MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.00

    In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…

  • CVE-2023-21133MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.00

    In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…

  • CVE-2023-21132MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.00

    In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution…

  • CVE-2023-20772MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441796; Issue ID: ALPS07441796.

  • CVE-2023-20926MedMar 24, 2023
    risk 0.44cvss 6.8epss 0.00

    In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional…

  • CVE-2022-47462MedMar 10, 2023
    risk 0.44cvss 6.7epss 0.00

    In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

  • CVE-2022-47461MedMar 10, 2023
    risk 0.44cvss 6.7epss 0.00

    In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

  • CVE-2022-47341MedFeb 12, 2023
    risk 0.44cvss 6.7epss 0.00

    In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

  • CVE-2022-47339MedFeb 12, 2023
    risk 0.44cvss 6.7epss 0.00

    In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed.