VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 190 of 475
  • CVE-2023-44210MedOct 4, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 29258, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-35677MedSep 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not…

  • CVE-2023-20826MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550.

  • CVE-2023-20825MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID:…

  • CVE-2023-20824MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID:…

  • CVE-2023-38466MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-38465MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-38463MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38462MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38461MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38457MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38454MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-38448MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38447MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38446MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38445MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

  • CVE-2023-38442MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-38441MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-38440MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-38439MedSep 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges