Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-22257 Improper Privilege Management vulnerability in Huawei Emui, Harmonyos and Magic UI
The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
network
low complexity
huawei CWE-269
7.5
2022-04-08 CVE-2021-36290 Improper Privilege Management vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability.
local
low complexity
dell CWE-269
6.7
2022-04-08 CVE-2021-36293 Improper Privilege Management vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability.
local
low complexity
dell CWE-269
6.7
2022-04-06 CVE-2022-20782 Improper Privilege Management vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device.
network
low complexity
cisco CWE-269
6.5
2022-04-06 CVE-2022-26251 Improper Privilege Management vulnerability in Synametrics Synaman
The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.
network
low complexity
synametrics CWE-269
7.2
2022-03-30 CVE-2021-39772 Improper Privilege Management vulnerability in Google Android 12.0
In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check.
low complexity
google CWE-269
8.8
2022-03-30 CVE-2021-39782 Improper Privilege Management vulnerability in Google Android 12.0
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check.
local
low complexity
google CWE-269
7.8
2022-03-30 CVE-2021-39783 Improper Privilege Management vulnerability in Google Android 12.0
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check.
local
low complexity
google CWE-269
7.8
2022-03-30 CVE-2021-39784 Improper Privilege Management vulnerability in Google Android 12.0
In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check.
local
low complexity
google CWE-269
7.8
2022-03-18 CVE-2022-1003 Improper Privilege Management vulnerability in Mattermost
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
network
low complexity
mattermost CWE-269
4.9