CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 56 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42690 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42689 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42688 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42687 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42686 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42685 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42681 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-21393 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21389 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21388 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21378 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21373 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21341 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21328 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2023-21313 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2021-39810 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution… | ||
| CVE-2023-43488 | Hig | 0.51 | 7.9 | 0.00 | Oct 25, 2023 | The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without… | ||
| CVE-2023-27792 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2023 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories. | ||
| CVE-2023-40635 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2023 | In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-40634 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2023 | In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- risk 0.51cvss 7.8epss 0.00
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution…
- risk 0.51cvss 7.9epss 0.00
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without…
- risk 0.51cvss 7.8epss 0.00
An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.
- risk 0.51cvss 7.8epss 0.00
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed