VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 57 of 464
  • CVE-2023-35665HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-38464HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38460HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38459HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38458HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38456HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38455HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38453HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38452HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38451HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38450HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38449HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38444HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-38443HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

  • CVE-2023-24674HigSep 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

  • CVE-2023-21257HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21248HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-21247HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2023-30929HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

  • CVE-2023-30928HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.