VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 16 of 36
  • CVE-2025-12080MedOct 27, 2025
    risk 0.45cvss epss 0.00

    On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes is incorrectly implemented. Due to this misconfiguration,…

  • CVE-2026-30603MedApr 2, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, and exfiltrate data via supplying a crafted iu.sh script contained in an SD card.

  • CVE-2025-56438MedOct 24, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackers to escalate privileges to root via supplying a crafted update.tar archive file stored on a FAT32-formatted SD card.

  • CVE-2025-5833MedJun 25, 2025
    risk 0.44cvss 6.8epss 0.00

    Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to…

  • CVE-2025-5832MedJun 25, 2025
    risk 0.44cvss 6.8epss 0.00

    Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required…

  • CVE-2024-52548MedDec 3, 2024
    risk 0.44cvss 6.7epss 0.00

    An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.

  • CVE-2023-20236MedSep 13, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this…

  • CVE-2023-30562MedJul 13, 2023
    risk 0.44cvss 6.7epss 0.00

    A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.

  • CVE-2023-22315MedJan 30, 2023
    risk 0.44cvss 6.7epss 0.00

    Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary code.

  • CVE-2022-0031MedNov 9, 2022
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.

  • CVE-2022-20774MedApr 6, 2022
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an…

  • CVE-2021-39689MedMar 16, 2022
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-44850MedFeb 10, 2022
    risk 0.44cvss 6.8epss 0.00

    On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the boot header stored on an SD card so that…

  • CVE-2021-41203HigNov 5, 2021
    risk 0.44cvss 7.8epss 0.00

    TensorFlow is an open source platform for machine learning. In affected versions an attacker can trigger undefined behavior, integer overflows, segfaults and `CHECK`-fail crashes if they can change saved checkpoints from outside of TensorFlow. This is because the checkpoints…

  • CVE-2021-33887MedJun 15, 2021
    risk 0.44cvss 6.8epss 0.00

    Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.

  • CVE-2020-24395MedMay 20, 2021
    risk 0.44cvss 6.8epss 0.00

    The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device.

  • CVE-2020-13178MedAug 11, 2020
    risk 0.44cvss 6.7epss 0.00

    A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain elevated privileges via execution in the context of the PCoIP…

  • CVE-2020-3220MedJun 3, 2020
    risk 0.44cvss 6.8epss 0.01

    A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions to an affected…

  • CVE-2019-16398MedSep 19, 2019
    risk 0.44cvss 6.8epss 0.01

    On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.

  • CVE-2019-1932MedJul 6, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamically loaded modules. An…