CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2022-22757 MEDIUM
Firefox < 97.0 - Remote Browser Control via WebDriver Host Header Spoofing
CVSS 6.5
CVE-2022-23556 HIGH
CodeIgniter 4.0.0-4.2.10 - IP Address Spoofing via Reverse Proxy Misconfiguration
CVSS 7.0
CVE-2022-46422 MEDIUM
Netgear WNR2000 Firmware < 1.2.3.7 - Authenticated Denial of Service via Crafted Firmware Image Upload
CVSS 4.8
CVE-2022-46139 MEDIUM
TP-Link TL-WR940N V4 < 3.16.9 - Authenticated Denial of Service via Firmware Update
CVSS 6.5
CVE-2022-38873 HIGH
D-Link DAP-2310 Firmware < 2.10rc036 - Denial of Service via Crafted Firmware Header
CVSS 7.5
CVE-2022-26579 MEDIUM
PAX PayDroid 7.1.1 Virgo V04.3.26T1 - Unauthenticated Unsigned Package Installation
CVSS 6.0
CVE-2022-41961 MEDIUM
BigBlueButton < 2.4-rc-6 - Ineffective User Ban Enforcement via Shared extId
CVSS 4.3
CVE-2022-41960 MEDIUM
BigBlueButton < 2.4.3 - Denial of Service via validateAuthToken Meteor Call
CVSS 4.3
CVE-2022-46692 MEDIUM
iCloud < 14.1 - Same Origin Policy Bypass via Malicious Web Content
CVSS 5.5
CVE-2022-37928 HIGH
HPE Nimble Storage Hybrid/Secondary Flash Arrays < 5.2.1.900 Data Authenticity Verification Issue
CVSS 8.0
CVE-2022-39909 HIGH
Samsung Gear IconX PC Manager < 2.1.221019.51 - Arbitrary File Creation via Symbolic Link
CVSS 7.1
CVE-2022-23491 MEDIUM
certifi 2017.11.5-2022.12.7 - Insufficient Verification of Data Authenticity
CVSS 6.8
CVE-2022-31877 HIGH
MSI Center 1.0.41.0 - Privilege Escalation via Crafted TCP Packet
CVSS 8.8
CVE-2022-41156 HIGH
OndiskPlayerAgent - Remote Code Execution via Insufficient URL Verification
CVSS 7.8
CVE-2022-36111 MEDIUM
immudb < 1.4.1 - Insufficient Verification of Data Authenticity via Falsified Proof
CVSS 5.4
CVE-2022-39199 MEDIUM
immudb < 1.4.1 - Insufficient Verification of Data Authenticity via Server UUID Spoofing
CVSS 5.8
CVE-2022-3703 HIGH
ETIC Telecom Remote Access Server Firmware < 4.5.0 - Insufficient Verification of Data Authenticity
CVSS 7.6
CVE-2022-0031 MEDIUM
Cortex XSOAR - Local Privilege Escalation via Insufficient Verification of Data Authenticity
CVSS 6.7
CVE-2022-27513 HIGH
Citrix Gateway and Application Delivery Controller Firmware 12.1 - Remote Desktop Takeover via Phishing
CVSS 8.3
CVE-2022-26122 MEDIUM
FortiClient/FortiMail/FortiOS AV <6.2.168 & <6.4.274 - Auth Bypass
CVSS 4.7
CVE-2022-34845 LOW
Robustel R1510 Firmware 3.1.16 and 3.3.0 - Arbitrary Firmware Update via sysupgrade Functionality
CVSS 2.7
CVE-2022-36360 HIGH
Siemens LOGO! 8 BM Firmware <8.3 - Insufficient Firmware Update Authenticity Verification
CVSS 7.5
CVE-2022-20396 MEDIUM
Android 12L 13 - Unauthenticated Bluetooth Discoverability Bypass via SettingsActivity
CVSS 5.5
CVE-2022-36130 CRITICAL
HashiCorp Boundary <0.10.1 - Privilege Escalation
CVSS 9.9
CVE-2022-38625 HIGH
Patlite NH-FB < 1.46 - Authenticated Firmware Validation Bypass via Firmware Upload
CVSS 8.8
Details
Vulnerabilities 658