VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 25 of 41
  • CVE-2017-12740MedDec 26, 2017
    risk 0.38cvss 5.9epss 0.01

    Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

  • CVE-2016-1731MedMar 14, 2016
    risk 0.38cvss 5.9epss 0.01

    Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.

  • CVE-2016-0818MedMar 12, 2016
    risk 0.38cvss 5.9epss 0.00

    The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows…

  • CVE-2015-8254MedDec 27, 2015
    risk 0.38cvss 5.9epss 0.00

    The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes it easier for man-in-the-middle attackers to (1) initiate a false alarm or (2) deactivate an alarm by modifying the client-server data stream.

  • CVE-2026-81706MedAug 27, 2026
    risk 0.37cvss 6.8epss 0.00

    openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the…

  • CVE-2026-73419MedAug 12, 2026
    risk 0.37cvss 6.8epss 0.00

    NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On…

  • CVE-2026-50573MedJun 25, 2026
    risk 0.37cvss 6.8epss 0.00

    pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. When a package is already locked with an integrity…

  • CVE-2024-54111MedDec 12, 2024
    risk 0.37cvss 5.7epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-40644MedJul 18, 2024
    risk 0.37cvss 6.8epss 0.00

    gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative…

  • CVE-2023-49087MedNov 30, 2023
    risk 0.37cvss 6.8epss 0.00

    xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree…

  • CVE-2023-46446MedNov 14, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."

  • CVE-2022-23491MedDec 7, 2022
    risk 0.37cvss 6.8epss 0.01

    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from…

  • CVE-2019-19160MedJun 29, 2020
    risk 0.37cvss 5.7epss 0.01

    Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).

  • CVE-2026-44725MedAug 20, 2026
    risk 0.36cvss 6.6epss 0.00

    EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was…

  • CVE-2026-74890MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to…

  • CVE-2025-31356MedAug 11, 2026
    risk 0.36cvss —epss 0.00

    Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data…

  • CVE-2025-52638MedMar 16, 2026
    risk 0.36cvss 5.6epss 0.00

    HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning…

  • CVE-2025-2346MedMar 16, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain Handler. The manipulation of the argument Domain Name leads to origin validation error. The attack…

  • CVE-2024-38432MedJul 30, 2024
    risk 0.36cvss 5.5epss 0.00

    Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File

  • CVE-2022-44420MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges.