CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 60 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-20912 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2022-20547 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20522 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20508 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20506 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20503 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2022-42778 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed. | ||
| CVE-2022-42777 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-42776 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed. | ||
| CVE-2022-39102 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39101 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39100 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39099 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39098 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39097 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39096 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39095 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39094 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39093 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39092 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
- risk 0.51cvss 7.8epss 0.00
In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- risk 0.51cvss 7.8epss 0.00
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.51cvss 7.8epss 0.00
In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.51cvss 7.8epss 0.00
In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.