VYPR

CWE-494

Download of Code Without Integrity Check

BaseDraftLikelihood: Medium

Description

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-184 · CAPEC-185 · CAPEC-186 · CAPEC-187 · CAPEC-533 · CAPEC-538 · CAPEC-657 · CAPEC-662 · CAPEC-691 · CAPEC-692 · CAPEC-693 · CAPEC-695

CVEs mapped to this weakness (216)

page 6 of 11
  • CVE-2019-19166HigMay 6, 2020
    risk 0.51cvss 7.8epss 0.00

    Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.

  • CVE-2019-9534HigOct 10, 2019
    risk 0.51cvss 7.8epss 0.00

    The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware…

  • CVE-2019-12162HigJul 23, 2019
    risk 0.51cvss 7.8epss 0.00

    Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe.

  • CVE-2018-4009HigApr 15, 2019
    risk 0.51cvss 7.8epss 0.00

    An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to…

  • CVE-2026-55698HigJun 25, 2026
    risk 0.50cvss 8.8epss 0.00

    pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env…

  • CVE-2026-33075HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.00

    FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository…

  • CVE-2022-45442HigNov 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response…

  • CVE-2022-36359HigAug 3, 2022
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from…

  • CVE-2025-9319HigSep 11, 2025
    risk 0.49cvss 7.5epss 0.00

    A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions.

  • CVE-2024-50696HigFeb 26, 2025
    risk 0.49cvss 7.5epss 0.00

    SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

  • CVE-2024-52331HigJan 23, 2025
    risk 0.49cvss 7.5epss 0.00

    ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

  • CVE-2024-47867HigOct 10, 2024
    risk 0.49cvss 7.5epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious code. If an attacker gains access to the remote URL from which…

  • CVE-2024-39348HigJun 28, 2024
    risk 0.49cvss 7.5epss 0.00

    Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.

  • CVE-2024-33118HigMay 6, 2024
    risk 0.49cvss 7.5epss 0.00

    LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.

  • CVE-2023-5592HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of…

  • CVE-2023-46143HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

  • CVE-2023-46887HigNov 29, 2023
    risk 0.49cvss 7.5epss 0.00

    In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.

  • CVE-2023-40254HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from…

  • CVE-2023-24503HigApr 17, 2023
    risk 0.49cvss 7.5epss 0.00

    Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

  • CVE-2023-24500HigApr 17, 2023
    risk 0.49cvss 7.5epss 0.00

    Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.