Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-04-12 CVE-2021-39797 Improper Privilege Management vulnerability in Google Android 12.0/12.1
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code.
local
low complexity
google CWE-269
7.8
2022-04-12 CVE-2021-39807 Improper Privilege Management vulnerability in Google Android
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check.
local
low complexity
google CWE-269
7.8
2022-04-11 CVE-2022-22257 Improper Privilege Management vulnerability in Huawei Emui, Harmonyos and Magic UI
The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
network
low complexity
huawei CWE-269
7.5
2022-04-08 CVE-2021-36290 Improper Privilege Management vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability.
local
low complexity
dell CWE-269
6.7
2022-04-08 CVE-2021-36293 Improper Privilege Management vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability.
local
low complexity
dell CWE-269
6.7
2022-04-06 CVE-2022-20782 Improper Privilege Management vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device.
network
low complexity
cisco CWE-269
6.5
2022-04-06 CVE-2022-26251 Improper Privilege Management vulnerability in Synametrics Synaman
The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.
network
low complexity
synametrics CWE-269
7.2
2022-03-30 CVE-2021-39772 Improper Privilege Management vulnerability in Google Android 12.0
In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check.
low complexity
google CWE-269
8.8
2022-03-30 CVE-2021-39782 Improper Privilege Management vulnerability in Google Android 12.0
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check.
local
low complexity
google CWE-269
7.8
2022-03-30 CVE-2021-39783 Improper Privilege Management vulnerability in Google Android 12.0
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check.
local
low complexity
google CWE-269
7.8