VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 19 of 36
  • CVE-2023-37920HigJul 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an…

  • CVE-2022-4537MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login…

  • CVE-2023-27979MedMar 21, 2023
    risk 0.42cvss 6.5epss 0.00

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server…

  • CVE-2023-27977MedMar 21, 2023
    risk 0.42cvss 6.5epss 0.00

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP…

  • CVE-2023-0350MedMar 13, 2023
    risk 0.42cvss 6.5epss 0.00

    Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to upload a file to the device by changing the extension of a malicious file to an accepted file type.

  • CVE-2023-23941HigFeb 3, 2023
    risk 0.42cvss 7.5epss 0.00

    SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order.…

  • CVE-2021-26403MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.

  • CVE-2022-3346MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain…

  • CVE-2022-34471MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior…

  • CVE-2022-22757MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. *This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*.…

  • CVE-2022-46139MedDec 20, 2022
    risk 0.42cvss 6.5epss 0.00

    TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

  • CVE-2022-2255HigAug 25, 2022
    risk 0.42cvss 7.5epss 0.01

    A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.

  • CVE-2022-32252MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to…

  • CVE-2022-22846HigJan 10, 2022
    risk 0.42cvss 7.5epss 0.01

    The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a query.

  • CVE-2020-10137MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the…

  • CVE-2019-8921MedNov 29, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting…

  • CVE-2021-38396MedOct 4, 2021
    risk 0.42cvss 6.5epss 0.00

    The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.

  • CVE-2021-34572MedSep 16, 2021
    risk 0.42cvss 6.5epss 0.00

    Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.

  • CVE-2021-40491MedSep 3, 2021
    risk 0.42cvss 6.5epss 0.01

    The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.

  • CVE-2021-21588MedJul 12, 2021
    risk 0.42cvss 6.5epss 0.00

    Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and…