VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 28 of 36
  • CVE-2023-32993MedMay 16, 2023
    risk 0.31cvss 4.8epss 0.00

    Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-46422MedDec 20, 2022
    risk 0.31cvss 4.8epss 0.00

    An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

  • CVE-2022-39199MedNov 22, 2022
    risk 0.31cvss 5.8epss 0.00

    immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. SDK does not…

  • CVE-2022-26122MedNov 2, 2022
    risk 0.31cvss 4.7epss 0.00

    An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad…

  • CVE-2022-2789MedAug 19, 2022
    risk 0.31cvss 4.7epss 0.00

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.

  • CVE-2022-22567MedFeb 9, 2022
    risk 0.31cvss 4.7epss 0.00

    Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.

  • CVE-2019-18905MedApr 3, 2020
    risk 0.31cvss 4.8epss 0.01

    A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue…

  • CVE-2020-3174MedFeb 26, 2020
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability…

  • CVE-2026-42206MedMay 8, 2026
    risk 0.30cvss epss 0.00

    Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerator::generate() and includes it in the authorization request sent to the identity…

  • CVE-2025-25188MedFeb 10, 2025
    risk 0.30cvss epss 0.00

    Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DNSSEC verification in the client library, stub resolver, or recursive resolver.…

  • CVE-2022-28385MedJun 8, 2022
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can manipulate the content of the emulated CD-ROM drive (containing the Windows and macOS client software). The content of this emulated CD-ROM drive is stored as…

  • CVE-2021-21739MedAug 5, 2021
    risk 0.30cvss 4.6epss 0.00

    A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system…

  • CVE-2026-45792MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directory with highest priority and without…

  • CVE-2026-41164MedMay 26, 2026
    risk 0.29cvss 4.4epss 0.00

    nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key…

  • CVE-2026-25602MedMay 20, 2026
    risk 0.29cvss 4.4epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49;…

  • CVE-2026-22703MedJan 10, 2026
    risk 0.29cvss 5.5epss 0.00

    Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key. When…

  • CVE-2024-53267MedNov 26, 2024
    risk 0.29cvss 5.5epss 0.00

    sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients…

  • CVE-2022-48431MedMar 29, 2023
    risk 0.29cvss 4.5epss 0.00

    In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.

  • CVE-2021-26396MedJan 11, 2023
    risk 0.29cvss 4.4epss 0.00

    Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.

  • CVE-2021-26368MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.