VYPR

CWE-494

Download of Code Without Integrity Check

BaseDraftLikelihood: Medium

Description

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-184 · CAPEC-185 · CAPEC-186 · CAPEC-187 · CAPEC-533 · CAPEC-538 · CAPEC-657 · CAPEC-662 · CAPEC-691 · CAPEC-692 · CAPEC-693 · CAPEC-695

CVEs mapped to this weakness (216)

page 3 of 11
  • CVE-2025-11493HigOct 16, 2025
    risk 0.57cvss 8.8epss 0.00

    The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for…

  • CVE-2025-57431HigSep 22, 2025
    risk 0.57cvss 8.8epss 0.00

    The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying…

  • CVE-2025-53520HigAug 8, 2025
    risk 0.57cvss 8.8epss 0.00

    The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks.…

  • CVE-2025-7620HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.00

    The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute…

  • CVE-2024-43169HigMar 3, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code.

  • CVE-2024-30206HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating…

  • CVE-2023-39474HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability…

  • CVE-2023-47353HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.

  • CVE-2022-28944HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan…

  • CVE-2022-24644HigMar 10, 2022
    risk 0.57cvss 8.8epss 0.02

    ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.

  • CVE-2020-7874HigSep 9, 2021
    risk 0.57cvss 8.8epss 0.01

    Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.

  • CVE-2020-7873HigSep 9, 2021
    risk 0.57cvss 8.8epss 0.01

    Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution.

  • CVE-2020-2320CriDec 3, 2020
    risk 0.57cvss 9.8epss 0.01

    Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

  • CVE-2020-28213HigNov 19, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.

  • CVE-2020-7831HigAug 24, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to download any file. The attacker is able to use startup menu directory via directory traversal for automatic execution. The victim user need to reboot, however.

  • CVE-2020-10926HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of firmware updates.…

  • CVE-2020-7826HigJul 17, 2020
    risk 0.57cvss 8.8epss 0.01

    EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting the arguments to the vulnerable method. This can be leveraged for code execution. When the vulnerable method is called, they fail to…

  • CVE-2020-9474HigMay 7, 2020
    risk 0.57cvss 8.8epss 0.02

    The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows remote code execution via the backup functionality in the web frontend. By using an exploit chain, an attacker with access to the network can get root access on the gateway.

  • CVE-2019-12809HigAug 15, 2019
    risk 0.57cvss 8.8epss 0.01

    Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.

  • CVE-2018-19234HigDec 20, 2018
    risk 0.57cvss 8.8epss 0.03

    The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute arbitrary code with SYSTEM privileges via vectors related to missing update validation.