VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 2 of 41
  • CVE-2022-30315CriJul 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053, there is a Honeywell Experion PKS Safety Manager insufficient logic security controls issue. The affected components are…

  • CVE-2022-30273CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.00

    The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode…

  • CVE-2022-29958CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with…

  • CVE-2022-31801CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

  • CVE-2022-31800CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.02

    An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

  • CVE-2022-31813CriJun 9, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

  • CVE-2020-14115CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

  • CVE-2022-25262CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

  • CVE-2021-29655CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.

  • CVE-2020-7878CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.

  • CVE-2020-24672CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .

  • CVE-2021-37421CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.

  • CVE-2020-28900CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.02

    Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

  • CVE-2020-26547CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.01

    Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver…

  • CVE-2020-7487CriApr 22, 2020
    risk 0.64cvss 9.8epss 0.01

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.

  • CVE-2019-20530CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (December 2019).

  • CVE-2019-5613CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.01

    In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated.

  • CVE-2019-2289CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.01

    Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2019-6695CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.

  • CVE-2018-19971CriApr 16, 2019
    risk 0.64cvss 9.8epss 0.03

    JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.