CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2022-2255 HIGH
mod_wsgi < 4.9.3 - Unauthenticated Header Spoofing via X-Client-IP
CVSS 7.5
CVE-2022-2793 MEDIUM
Emerson Electric's Proficy Machine Edition <9.00 - Info Disclosure
CVSS 5.9
CVE-2022-2789 MEDIUM
Emerson Electric's Proficy Machine Edition < 9.0.0 - Insufficient Verification of Data Authenticity
CVSS 4.7
CVE-2022-28757 HIGH
Zoom Client for Meetings <5.11.6 - Privilege Escalation
CVSS 8.8
CVE-2022-30262 HIGH
Emerson ControlWave PAC and Micro Firmware < 2022-05-02 - Insufficient Firmware Integrity Verification
CVSS 7.8
CVE-2022-30264 CRITICAL
Emerson ROC/FloBoss RTU <2022-05-02 - Unauthenticated Arbitrary File Operations via ROC Opcode 203
CVSS 9.8
CVE-2022-37008 HIGH
Huawei EMUI - Insufficient Verification of Data Authenticity in Recovery Module
CVSS 7.5
CVE-2022-30315 CRITICAL
Honeywell Experion PKS Safety Manager <= 2022-05-06 - RCE via Safety Builder Protocol
CVSS 9.8
CVE-2022-30272 HIGH
Motorola ACE1000 RTU - Insufficient Firmware Integrity Verification
CVSS 7.2
CVE-2022-30269 HIGH
Motorola ACE1000 RTUs through 2022-05-02 - Insufficient Verification of Data Authenticity
CVSS 8.8
CVE-2022-30273 CRITICAL
Motorola MDLC - Insufficient Verification of Data Authenticity in Legacy Encryption Mode
CVSS 9.8
CVE-2022-29958 CRITICAL
JTEKT TOYOPUC PLCs through 2022-04-29 - Unauthenticated Arbitrary Code Execution via CMPLink/TCP Protocol
CVSS 9.8
CVE-2022-28370 HIGH
Verizon 5G Home LVSKIHP ODU 3.33.101.0 - Code Injection
CVSS 7.5
CVE-2022-34763 MEDIUM
Schneider Electric OPC UA Module for M580 <1.10 & X80 Advanced RTU >=2.01 - Data Authenticity Verification Bypass
CVSS 5.9
CVE-2022-31598 MEDIUM
SAP Business Objects <420 - Info Disclosure
CVSS 5.4
CVE-2022-20829 CRITICAL
Cisco ASA and ASDM - Authenticated Arbitrary Code Execution via Malicious ASDM Image
CVSS 9.1
CVE-2022-31801 CRITICAL
Phoenixcontact Multiprog - Data Authenticity Bypass
CVSS 9.8
CVE-2022-31800 CRITICAL
Phoenix Contact ProConOS/ProConOS eCLR Firmware - Unauthenticated Remote Code Execution via Malicious Logic Upload
CVSS 9.8
CVE-2022-32252 MEDIUM
SINEMA Remote Connect Server < 3.1 - Authenticated Privilege Escalation via Unverified Update Package
CVSS 6.5
CVE-2022-31813 CRITICAL
Apache HTTP Server < 2.4.54 - Insufficient Verification of Data Authenticity via X-Forwarded-* Headers
CVSS 9.8
CVE-2022-28385 MEDIUM
Verbatim drives <2022-03-31 - Info Disclosure
CVSS 4.6
CVE-2022-29220 MEDIUM
github-action-merge-dependabot <3.2.0 - Info Disclosure
CVSS 6.5
CVE-2022-24889 LOW
Nextcloud Server < 21.0.8 - Insufficient Verification of Data Authenticity
CVSS 2.4
CVE-2022-20795 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via DTLS Tunnel Processing
CVSS 5.8
CVE-2022-26516 HIGH
Redlion DA50N Firmware - Authenticated Insufficient Verification of Data Authenticity via Web Update Interface
CVSS 8.4
Details
Vulnerabilities 658