VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 56 of 464
  • CVE-2023-42690HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42689HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42688HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42687HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42686HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42685HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-42681HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-21393HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21389HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21388HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21378HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21373HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21341HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21328HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2023-21313HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2021-39810HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution…

  • CVE-2023-43488HigOct 25, 2023
    risk 0.51cvss 7.9epss 0.00

    The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without…

  • CVE-2023-27792HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.

  • CVE-2023-40635HigOct 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-40634HigOct 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed