VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 5 of 36
  • CVE-2023-27360HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.00

    NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2024-27773HigMar 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE

  • CVE-2015-8371HigSep 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached. The cache key is derived from the…

  • CVE-2023-2987CriMay 31, 2023
    risk 0.57cvss 9.8epss 0.01

    The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the…

  • CVE-2023-27982HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.00

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead…

  • CVE-2022-31877HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

  • CVE-2022-38625HigAug 29, 2022
    risk 0.57cvss 8.8epss 0.00

    Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code. NOTE: the…

  • CVE-2022-28757HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-30269HigJul 26, 2022
    risk 0.57cvss 8.8epss 0.00

    Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files)…

  • CVE-2021-26625HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this…

  • CVE-2022-22994HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.02

    A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by…

  • CVE-2021-45419HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.00

    Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.

  • CVE-2021-37188HigDec 10, 2021
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.

  • CVE-2021-26608HigSep 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.

  • CVE-2021-39158HigAug 23, 2021
    risk 0.57cvss 8.8epss 0.01

    NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to install it within NVCaffe.

  • CVE-2021-33712HigJun 8, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2). The configuration of the SAML module does not properly check various restrictions and validations imposed by an identity provider. This could allow a remote authenticated attacker to escalate…

  • CVE-2021-32665HigJun 3, 2021
    risk 0.57cvss 8.8epss 0.00

    wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unverified. This occurs when: - Self user is added to a new conversation - Self user is added to an…

  • CVE-2020-12406HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox…

  • CVE-2020-6081HigMay 7, 2020
    risk 0.57cvss 8.8epss 0.02

    An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this…

  • CVE-2020-6443HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.