VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 62 of 464
  • CVE-2022-20329HigAug 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20282HigAug 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20281HigAug 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20274HigAug 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-206470146

  • CVE-2022-20360HigAug 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20349HigAug 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20348HigAug 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-26429HigAug 1, 2022
    risk 0.51cvss 7.8epss 0.00

    In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2022-21777HigJul 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.

  • CVE-2022-20204HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2022-20138HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution…

  • CVE-2022-20133HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39738HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20004HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20093HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498868;…

  • CVE-2022-20084HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-39808HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2022-20002HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39768HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-39758HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…