VYPR

CWE-494

Download of Code Without Integrity Check

BaseDraftLikelihood: Medium

Description

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-184 · CAPEC-185 · CAPEC-186 · CAPEC-187 · CAPEC-533 · CAPEC-538 · CAPEC-657 · CAPEC-662 · CAPEC-691 · CAPEC-692 · CAPEC-693 · CAPEC-695

CVEs mapped to this weakness (237)

page 10 of 12
  • CVE-2023-46144MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.00

    A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.

  • CVE-2023-5630MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.00

    A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.

  • CVE-2022-31324MedSep 13, 2022
    risk 0.42cvss 6.5epss 0.00

    An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.

  • CVE-2021-3485MedMay 24, 2021
    risk 0.42cvss 6.4epss 0.01

    An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects:…

  • CVE-2022-38199MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.00

    A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cases allow a remote, unauthenticated attacker to induce an unsuspecting victim to launch a process in the victim's PATH environment. Current browsers provide…

  • CVE-2022-37908MedDec 12, 2022
    risk 0.38cvss 5.8epss 0.00

    An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.

  • CVE-2017-12740MedDec 26, 2017
    risk 0.38cvss 5.9epss 0.01

    Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

  • CVE-2021-30669MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may bypass Gatekeeper checks.

  • CVE-2021-30658MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks.

  • CVE-2020-25266MedDec 2, 2020
    risk 0.36cvss 5.5epss 0.00

    AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.

  • CVE-2020-7817MedAug 6, 2020
    risk 0.36cvss 5.5epss 0.00

    MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity verification of the files.

  • CVE-2010-3440MedNov 12, 2019
    risk 0.36cvss 5.5epss 0.00

    babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.

  • CVE-2026-84666MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording…

  • CVE-2026-84664MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.

  • CVE-2026-3428MedApr 16, 2026
    risk 0.35cvss —epss 0.00

    A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an…

  • CVE-2026-1878MedMar 12, 2026
    risk 0.35cvss —epss 0.00

    An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race…

  • CVE-2023-45821MedOct 19, 2023
    risk 0.35cvss 5.4epss 0.00

    Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which the `registryIsDockerHub` function was only…

  • CVE-2026-93534MedSep 18, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch…

  • CVE-2025-15575MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows attackers to flash malicious firmware update files on the device. Initial analysis of the firmware update functionality does not show any cryptographic checks…

  • CVE-2024-47192MedAug 26, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.