VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 13 of 41
  • CVE-2024-37370HigJun 28, 2024
    risk 0.49cvss 7.5epss 0.01

    In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.

  • CVE-2024-33687HigJun 24, 2024
    risk 0.49cvss 7.5epss 0.00

    Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.

  • CVE-2023-52546HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52109HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-38552HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This…

  • CVE-2023-39347HigSep 27, 2023
    risk 0.49cvss 7.6epss 0.01

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to update pod labels can cause Cilium to apply incorrect network policies. This issue arises due to the fact that on pod update, Cilium incorrectly uses…

  • CVE-2022-3347HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.00

    DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

  • CVE-2022-38873HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta…

  • CVE-2022-3703HigNov 10, 2022
    risk 0.49cvss 7.6epss 0.00

    All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.

  • CVE-2022-36360HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This…

  • CVE-2022-37008HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.00

    The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.

  • CVE-2022-28370HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.00

    On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmware update for the device. /lib/functions/wnc_jsonsh/wnc_crtc_fw.sh has no cryptographic validation of the image, thus allowing an attacker…

  • CVE-2015-5236HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.01

    It was discovered that the IcedTea-Web used codebase attribute of the tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass…

  • CVE-2020-14116HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.00

    An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this.

  • CVE-2021-4031HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.00

    Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed without any verification.

  • CVE-2021-46559HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.00

    The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

  • CVE-2020-19769HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from victim users via a crafted script.

  • CVE-2020-19768HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from victim users via a crafted script.

  • CVE-2021-33840HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.

  • CVE-2021-29462HigApr 20, 2021
    risk 0.49cvss 7.6epss 0.01

    The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by…