VYPR

CWE-354

Improper Validation of Integrity Check Value

BaseDraftLikelihood: Medium

Description

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Improper validation of checksums before use results in an unnecessary risk that can easily be mitigated. The protocol specification describes the algorithm used for calculating the checksum. It is then a simple matter of implementing the calculation and verifying that the calculated checksum and the received checksum match. Improper verification of the calculated checksum and the received checksum can lead to far greater consequences.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-145 · CAPEC-463 · CAPEC-75

CVEs mapped to this weakness (194)

page 10 of 10
  • CVE-2026-25934MedFeb 9, 2026
    risk 0.21cvss 4.3epss 0.00

    go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted…

  • CVE-2024-23462LowMay 2, 2024
    risk 0.21cvss 3.3epss 0.00

    An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector binary and thus removing client functionality.This issue affects Client Connector on MacOS: before 3.4.

  • CVE-2019-10155LowJun 12, 2019
    risk 0.20cvss 3.1epss 0.01

    The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This…

  • CVE-2017-12973LowAug 20, 2017
    risk 0.20cvss 3.1epss 0.01

    Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.

  • CVE-2025-25183LowFeb 7, 2025
    risk 0.10cvss 2.6epss 0.00

    vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements can lead to hash collisions, resulting in cache reuse, which can interfere with subsequent responses and cause unintended behavior. Prefix caching makes use…

  • CVE-2025-4616LowNov 14, 2025
    risk 0.07cvss —epss 0.00

    An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.

  • CVE-2026-54578LowSep 17, 2026
    risk 0.06cvss —epss 0.00

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able…

  • CVE-2026-16317MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer…

  • CVE-2026-13385CriJul 15, 2026
    risk 0.00cvss —epss 0.00

    An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for…

  • CVE-2024-52550HigNov 13, 2024
    risk 0.00cvss 8.0epss 0.00

    Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile)…

  • CVE-2024-25678CriFeb 9, 2024
    risk 0.00cvss 9.8epss 0.00

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

  • CVE-2023-45150MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It…

  • CVE-2023-31439MedJun 13, 2023
    risk 0.00cvss 5.3epss 0.00

    An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the…

  • CVE-2023-31438MedJun 13, 2023
    risk 0.00cvss 5.3epss 0.00

    An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security…