VYPR

CWE-354

Improper Validation of Integrity Check Value

BaseDraftLikelihood: Medium

Description

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Improper validation of checksums before use results in an unnecessary risk that can easily be mitigated. The protocol specification describes the algorithm used for calculating the checksum. It is then a simple matter of implementing the calculation and verifying that the calculated checksum and the received checksum match. Improper verification of the calculated checksum and the received checksum can lead to far greater consequences.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-145 · CAPEC-463 · CAPEC-75

CVEs mapped to this weakness (183)

page 9 of 10
  • CVE-2025-3247MedApr 16, 2025
    risk 0.27cvss 5.3epss 0.00

    The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to…

  • CVE-2024-23461MedMay 2, 2024
    risk 0.27cvss 4.2epss 0.00

    An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4.

  • CVE-2023-34459MedJun 16, 2023
    risk 0.27cvss 5.3epss 0.00

    OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions are in use, it is possible to…

  • CVE-2020-1879LowMar 20, 2020
    risk 0.25cvss 3.9epss 0.00

    There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions…

  • CVE-2026-56416MedJul 22, 2026
    risk 0.24cvss 4.8epss 0.00

    In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight…

  • CVE-2026-33542MedMar 26, 2026
    risk 0.24cvss 4.8epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to…

  • CVE-2016-15028MedMar 12, 2023
    risk 0.24cvss 4.8epss 0.00

    A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper validation of integrity…

  • CVE-2024-23790LowJan 29, 2024
    risk 0.23cvss 3.5epss 0.00

    Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

  • CVE-2026-25934MedFeb 9, 2026
    risk 0.21cvss 4.3epss 0.00

    go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted…

  • CVE-2024-23462LowMay 2, 2024
    risk 0.21cvss 3.3epss 0.00

    An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector binary and thus removing client functionality.This issue affects Client Connector on MacOS: before 3.4.

  • CVE-2019-10155LowJun 12, 2019
    risk 0.20cvss 3.1epss 0.01

    The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This…

  • CVE-2017-12973LowAug 20, 2017
    risk 0.20cvss 3.1epss 0.01

    Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.

  • CVE-2025-25183LowFeb 7, 2025
    risk 0.10cvss 2.6epss 0.00

    vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements can lead to hash collisions, resulting in cache reuse, which can interfere with subsequent responses and cause unintended behavior. Prefix caching makes use…

  • CVE-2025-4616LowNov 14, 2025
    risk 0.07cvss epss 0.00

    An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.

  • CVE-2026-16317MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer…

  • CVE-2026-13385CriJul 15, 2026
    risk 0.00cvss epss 0.00

    An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for…

  • CVE-2024-52550HigNov 13, 2024
    risk 0.00cvss 8.0epss 0.00

    Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile)…

  • CVE-2024-25678CriFeb 9, 2024
    risk 0.00cvss 9.8epss 0.00

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

  • CVE-2023-45150MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It…

  • CVE-2023-31439MedJun 13, 2023
    risk 0.00cvss 5.3epss 0.00

    An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the…