VYPR

CWE-924

Improper Enforcement of Message Integrity During Transmission in a Communication Channel

BaseIncomplete

Description

The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.

Attackers might be able to modify the message and spoof the endpoint by interfering with the data as it crosses the network or by redirecting the connection to a system under their control.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (35)

page 2 of 2
  • CVE-2015-2968MedOct 31, 2023
    risk 0.38cvss 5.9epss 0.00

    LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.

  • CVE-2015-0897MedOct 31, 2023
    risk 0.38cvss 5.9epss 0.00

    LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM…

  • CVE-2023-3347MedJul 20, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to…

  • CVE-2023-22372MedMay 3, 2023
    risk 0.38cvss 5.9epss 0.00

    In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2026-39827MedMay 22, 2026
    risk 0.35cvss 6.5epss 0.00

    An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state…

  • CVE-2023-43297MedOct 2, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

  • CVE-2024-39229MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows…

  • CVE-2020-10635MedFeb 24, 2022
    risk 0.28cvss 4.3epss 0.00

    Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a model, the server transmits the model in plaintext.

  • CVE-2024-52288MedNov 11, 2024
    risk 0.26cvss 5.1epss 0.00

    libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In affected versions an unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` may be introduced into an active stream when they should not…

  • CVE-2023-30565LowJul 13, 2023
    risk 0.23cvss 3.5epss 0.00

    An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.

  • CVE-2023-26979LowAug 3, 2023
    risk 0.20cvss 3.1epss 0.00

    Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication.

  • CVE-2026-54891LowJul 2, 2026
    risk 0.17cvss 3.7epss 0.00

    Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) allows a network-positioned attacker to inject unauthenticated plaintext that the TLS client application later treats as…

  • CVE-2026-12576HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.

  • CVE-2021-3716LowMar 2, 2022
    risk 0.00cvss 3.1epss 0.01

    A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading…

  • CVE-2021-21390MedMar 19, 2021
    risk 0.00cvss 6.5epss 0.01

    MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-17T02-33-02Z, there is a vulnerability which enables MITM modification of request bodies that are meant to have…