CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,489)
page 190 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44210 | Med | 0.36 | 5.5 | 0.00 | Oct 4, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 29258, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | ||
| CVE-2023-35677 | Med | 0.36 | 5.5 | 0.00 | Sep 11, 2023 | In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-20826 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550. | ||
| CVE-2023-20825 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID:… | ||
| CVE-2023-20824 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID:… | ||
| CVE-2023-38466 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38465 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38463 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38462 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38461 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38457 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38454 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38448 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38447 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38446 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38445 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | ||
| CVE-2023-38442 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38441 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38440 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38439 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges |
- risk 0.36cvss 5.5epss 0.00
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 29258, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.
- risk 0.36cvss 5.5epss 0.00
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550.
- risk 0.36cvss 5.5epss 0.00
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID:…
- risk 0.36cvss 5.5epss 0.00
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID:…
- risk 0.36cvss 5.5epss 0.00
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges