VYPR

CWE-494

Download of Code Without Integrity Check

BaseDraftLikelihood: Medium

Description

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-184 · CAPEC-185 · CAPEC-186 · CAPEC-187 · CAPEC-533 · CAPEC-538 · CAPEC-657 · CAPEC-662 · CAPEC-691 · CAPEC-692 · CAPEC-693 · CAPEC-695

CVEs mapped to this weakness (216)

page 10 of 11
  • CVE-2024-47192MedAug 26, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

  • CVE-2023-28317MedMay 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.

  • CVE-2023-28818MedMar 24, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable…

  • CVE-2021-44168LowKEVJan 4, 2022
    risk 0.34cvss 3.3epss 0.01

    A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

  • CVE-2019-14845MedOct 8, 2019
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.

  • CVE-2026-32148MedApr 30, 2026
    risk 0.31cvss 5.9epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked…

  • CVE-2025-10539MedApr 28, 2026
    risk 0.31cvss 4.8epss 0.00

    Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request.…

  • CVE-2022-46430MedDec 20, 2022
    risk 0.31cvss 4.8epss 0.00

    TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

  • CVE-2022-46428MedDec 20, 2022
    risk 0.31cvss 4.8epss 0.00

    TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

  • CVE-2018-14620MedSep 10, 2018
    risk 0.31cvss 4.7epss 0.01

    The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of…

  • CVE-2020-9759MedMar 23, 2020
    risk 0.30cvss 4.6epss 0.00

    A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable…

  • CVE-2022-4261MedDec 8, 2022
    risk 0.29cvss 4.4epss 0.00

    Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing…

  • CVE-2017-12306MedNov 16, 2017
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit…

  • CVE-2024-33660MedNov 12, 2024
    risk 0.28cvss 4.3epss 0.00

    An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.

  • CVE-2017-13083MedOct 18, 2017
    risk 0.28cvss 5.3epss 0.01

    Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code

  • CVE-2025-47904MedFeb 24, 2026
    risk 0.27cvss 4.1epss 0.00

    Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.

  • CVE-2026-20056MedFeb 4, 2026
    risk 0.26cvss 4.0epss 0.00

    A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. …

  • CVE-2019-16760MedSep 30, 2019
    risk 0.23cvss 4.6epss 0.01

    Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `Cargo.toml` is ignored in Rust 1.25.0 and prior. When Rust 1.25.0 and prior is used Cargo may…

  • CVE-2025-66334LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66333LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.