VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 55 of 464
  • CVE-2024-0394HigApr 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege.  The vulnerability is caused by the product's implementation of…

  • CVE-2024-0038HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-48402HigDec 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40094HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40089HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2023-42748HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42747HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42746HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42745HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42743HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42740HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42739HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42738HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42736HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42696HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42695HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42694HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42693HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42692HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42691HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed