CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 55 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0394 | Hig | 0.51 | 7.8 | 0.00 | Apr 3, 2024 | Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege. The vulnerability is caused by the product's implementation of… | ||
| CVE-2024-0038 | Hig | 0.51 | 7.8 | 0.00 | Feb 16, 2024 | In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-48402 | Hig | 0.51 | 7.8 | 0.00 | Dec 8, 2023 | In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40094 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40089 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges… | ||
| CVE-2023-42748 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42747 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42746 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42745 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42743 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42740 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42739 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42738 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42736 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42696 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42695 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42694 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42693 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42692 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42691 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
- risk 0.51cvss 7.8epss 0.00
Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege. The vulnerability is caused by the product's implementation of…
- risk 0.51cvss 7.8epss 0.00
In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges…
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed