CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 58 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30917 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2023 | In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2023-30916 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2023 | In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2023-36624 | Hig | 0.51 | 7.8 | 0.00 | Jul 5, 2023 | Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement. | ||
| CVE-2023-20773 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07611449; Issue ID: ALPS07441735. | ||
| CVE-2023-21185 | Hig | 0.51 | 7.8 | 0.00 | Jun 28, 2023 | In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21149 | Hig | 0.51 | 7.8 | 0.00 | Jun 28, 2023 | In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-21123 | Hig | 0.51 | 7.8 | 0.00 | Jun 15, 2023 | In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction… | ||
| CVE-2023-21122 | Hig | 0.51 | 7.8 | 0.00 | Jun 15, 2023 | In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction… | ||
| CVE-2023-30864 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2023-30863 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48392 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48390 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2023-31826 | Hig | 0.51 | 7.8 | 0.00 | May 23, 2023 | Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data. | ||
| CVE-2022-48388 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48384 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48383 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | .In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48369 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48368 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48250 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2022-48249 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
- risk 0.51cvss 7.8epss 0.00
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement.
- risk 0.51cvss 7.8epss 0.00
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07611449; Issue ID: ALPS07441735.
- risk 0.51cvss 7.8epss 0.00
In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.51cvss 7.8epss 0.00
In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- risk 0.51cvss 7.8epss 0.00
In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- risk 0.51cvss 7.8epss 0.00
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
- risk 0.51cvss 7.8epss 0.00
In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
.In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.