VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 12 of 36
  • CVE-2022-3347HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.00

    DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

  • CVE-2022-38873HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta…

  • CVE-2022-3703HigNov 10, 2022
    risk 0.49cvss 7.6epss 0.00

    All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.

  • CVE-2022-36360HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This…

  • CVE-2022-37008HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.00

    The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.

  • CVE-2022-28370HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.00

    On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmware update for the device. /lib/functions/wnc_jsonsh/wnc_crtc_fw.sh has no cryptographic validation of the image, thus allowing an attacker…

  • CVE-2015-5236HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.01

    It was discovered that the IcedTea-Web used codebase attribute of the tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass…

  • CVE-2020-14116HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.00

    An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this.

  • CVE-2021-4031HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.00

    Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.

  • CVE-2021-46559HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.00

    The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

  • CVE-2020-19769HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from victim users via a crafted script.

  • CVE-2020-19768HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from victim users via a crafted script.

  • CVE-2021-33840HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.

  • CVE-2021-29462HigApr 20, 2021
    risk 0.49cvss 7.6epss 0.01

    The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by…

  • CVE-2020-15899HigJul 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.

  • CVE-2020-13272HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow

  • CVE-2020-14453HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.

  • CVE-2020-10831HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can trigger an update to arbitrary touch-screen firmware. The Samsung ID is SVE-2019-16013 (March 2020).

  • CVE-2019-3979HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can…

  • CVE-2019-10943HigAug 13, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V20.8), SIMATIC…