CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 61 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39091 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39090 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-20451 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:… | ||
| CVE-2022-20450 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-39111 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39110 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39109 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39108 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39107 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed. | ||
| CVE-2022-39080 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-38698 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-38670 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-38669 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-2985 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-20434 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2022 | There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242244028 | ||
| CVE-2022-20433 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2022 | There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221901 | ||
| CVE-2022-20432 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2022 | There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899 | ||
| CVE-2022-20431 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2022 | There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221238 | ||
| CVE-2022-20430 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2022 | There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221233 | ||
| CVE-2022-39119 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2022 | In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242244028
- risk 0.51cvss 7.8epss 0.00
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221901
- risk 0.51cvss 7.8epss 0.00
There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899
- risk 0.51cvss 7.8epss 0.00
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221238
- risk 0.51cvss 7.8epss 0.00
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221233
- risk 0.51cvss 7.8epss 0.00
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed