VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 1 of 36
  • CVE-2023-38831HigKEVAug 23, 2023
    risk 0.80cvss 7.8epss 0.98

    RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the…

  • CVE-2022-26871CriKEVMar 29, 2022
    risk 0.77cvss 9.8epss 0.20

    An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

  • CVE-2023-4699CriNov 6, 2023
    risk 0.65cvss 10.0epss 0.01

    Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC…

  • CVE-2026-50214CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

  • CVE-2025-15385CriJan 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.

  • CVE-2025-66255CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious…

  • CVE-2025-8038CriJul 22, 2025
    risk 0.64cvss 9.8epss 0.00

    Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

  • CVE-2024-23601CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-1554CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.00

    The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()`…

  • CVE-2023-36139CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-36134CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-25178CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2023-27748CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.01

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

  • CVE-2021-4226CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.

  • CVE-2022-36130CriSep 1, 2022
    risk 0.64cvss 9.9epss 0.00

    HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.

  • CVE-2022-30264CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer…

  • CVE-2022-30315CriJul 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053, there is a Honeywell Experion PKS Safety Manager insufficient logic security controls issue. The affected components are…

  • CVE-2022-30273CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.00

    The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode…

  • CVE-2022-29958CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with…

  • CVE-2022-31801CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.