CWE-494
Download of Code Without Integrity Check
Description
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-184 · CAPEC-185 · CAPEC-186 · CAPEC-187 · CAPEC-533 · CAPEC-538 · CAPEC-657 · CAPEC-662 · CAPEC-691 · CAPEC-692 · CAPEC-693 · CAPEC-695
CVEs mapped to this weakness (237)
page 7 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39348 | Hig | 0.49 | 7.5 | 0.00 | Jun 28, 2024 | Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors. | ||
| CVE-2024-33118 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController. | ||
| CVE-2023-5592 | Hig | 0.49 | 7.5 | 0.00 | Dec 14, 2023 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of… | ||
| CVE-2023-46143 | Hig | 0.49 | 7.5 | 0.00 | Dec 14, 2023 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. | ||
| CVE-2023-46887 | Hig | 0.49 | 7.5 | 0.00 | Nov 29, 2023 | In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability. | ||
| CVE-2023-40254 | Hig | 0.49 | 7.5 | 0.00 | Aug 11, 2023 | Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from… | ||
| CVE-2023-24503 | Hig | 0.49 | 7.5 | 0.00 | Apr 17, 2023 | Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. | ||
| CVE-2023-24500 | Hig | 0.49 | 7.5 | 0.00 | Apr 17, 2023 | Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. | ||
| CVE-2023-27025 | Hig | 0.49 | 7.5 | 0.00 | Apr 2, 2023 | An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server. | ||
| CVE-2021-45027 | Hig | 0.49 | 7.5 | 0.02 | Sep 1, 2022 | An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input. | ||
| CVE-2022-36671 | Hig | 0.49 | 7.5 | 0.00 | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API. | ||
| CVE-2022-22786 | Hig | 0.49 | 7.5 | 0.02 | May 18, 2022 | The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a… | ||
| CVE-2020-7875 | Hig | 0.49 | 7.5 | 0.01 | Oct 28, 2021 | DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution. | ||
| CVE-2020-15604 | Hig | 0.49 | 7.5 | 0.02 | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of… | ||
| CVE-2020-5772 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2020 | Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file. | ||
| CVE-2020-5398 | Hig | 0.49 | 7.5 | 0.89 | Jan 17, 2020 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute… | ||
| CVE-2019-3977 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2019 | RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly… | ||
| CVE-2019-5982 | Hig | 0.49 | 7.5 | 0.00 | Jul 5, 2019 | Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A successful exploitation may result in a malicious file being downloaded/executed. | ||
| CVE-2026-79963 | Hig | 0.48 | 7.4 | 0.00 | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading… | ||
| CVE-2026-22865 | Hig | 0.48 | 7.4 | 0.00 | Jan 16, 2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered… |
- risk 0.49cvss 7.5epss 0.00
Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.
- risk 0.49cvss 7.5epss 0.00
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.
- risk 0.49cvss 7.5epss 0.00
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of…
- risk 0.49cvss 7.5epss 0.00
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
- risk 0.49cvss 7.5epss 0.00
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
- risk 0.49cvss 7.5epss 0.00
Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from…
- risk 0.49cvss 7.5epss 0.00
Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
- risk 0.49cvss 7.5epss 0.00
Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
- risk 0.49cvss 7.5epss 0.00
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
- risk 0.49cvss 7.5epss 0.02
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.
- risk 0.49cvss 7.5epss 0.00
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
- risk 0.49cvss 7.5epss 0.02
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a…
- risk 0.49cvss 7.5epss 0.01
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.
- risk 0.49cvss 7.5epss 0.02
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of…
- risk 0.49cvss 7.5epss 0.01
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
- risk 0.49cvss 7.5epss 0.89
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute…
- risk 0.49cvss 7.5epss 0.01
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly…
- risk 0.49cvss 7.5epss 0.00
Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A successful exploitation may result in a malicious file being downloaded/executed.
- risk 0.48cvss 7.4epss 0.00
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading…
- risk 0.48cvss 7.4epss 0.00
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered…