CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2022-20774 MEDIUM
Cisco IP Phone 6800, 7800, and 8800 Series Multiplatform Firmware < 11.3.5 - Cross-Site Request Forgery
CVSS 6.8
CVE-2022-26871 CRITICAL KEV
Trend Micro Apex Central - Unauthenticated Arbitrary File Upload
CVSS 9.8
CVE-2022-0715 CRITICAL
APC Smart-UPS Family - Improper Authentication
CVSS 9.1
CVE-2022-25262 CRITICAL
JetBrains Hub < 2022.1.14434 - SAML Request Takeover via Insufficient Verification of Data Authenticity
CVSS 9.8
CVE-2022-22567 MEDIUM
Dell Alienware and G-Series Firmware - Authenticated BIOS Firmware Modification via Insufficient Verification
CVSS 4.7
CVE-2022-22994 HIGH
Western Digital My Cloud OS < 5.19.117 - Remote Code Execution via Unsecured HTTP Call
CVSS 8.8
CVE-2021-26403 MEDIUM
AMD EPYC 7001 Series Firmware - Insufficient Verification of Data Authenticity
CVSS 6.5
CVE-2021-26396 MEDIUM
AMD EPYC 7003 Firmware < milanpi-sp3_1.0.0.9 - Memory Integrity Loss via ASP Address Mapping
CVSS 4.4
CVE-2021-4226 CRITICAL
RSFirewall! < 1.1.25 - IP Address Spoofing via HTTP Header Manipulation
CVSS 9.8
CVE-2021-4122 MEDIUM
cryptsetup < 2.3.7 - Insufficient Verification of Data Authenticity in LUKS Header
CVSS 4.3
CVE-2021-26368 MEDIUM
AMD Ryzen 3/5/5300/5600/5700/5800/5900/5950 Firmware - Denial of Service via Trusted OS Process Type Check Bypass
CVSS 4.4
CVE-2021-27759 LOW
HCLTech BigFix Inventory 9.0 through 10.0.7.0 - Cross-Site Request Forgery
CVSS 2.3
CVE-2021-26625 HIGH
Nexacro 17.0.0-17.1.3.700 - Arbitrary File Download and Execute via Automatic Update Function
CVSS 8.8
CVE-2021-4031 HIGH
Syltek < 10.22.00 - Insufficient Verification of Data Authenticity in Payment System
CVSS 7.5
CVE-2021-39689 MEDIUM
Android - Local Privilege Escalation via Logic Error in odsign_main.cpp
CVSS 6.7
CVE-2021-24825 MEDIUM
WordPress Custom Content Shortcode <4.0.2 - Local File Inclusion
CVSS 4.3
CVE-2021-29655 CRITICAL
Pexip Infinity Connect < 1.8.0 - Unauthenticated Remote Code Execution via Provisioning Authenticity Bypass
CVSS 9.8
CVE-2021-44850 MEDIUM
Xilinx Zynq-7000 SoC Firmware - Buffer Overflow via Modified SD Boot Image Header
CVSS 6.8
CVE-2021-46559 HIGH
Moxa TN-5900 Firmware < 3.1 - Insufficient Verification of Data Authenticity
CVSS 7.5
CVE-2021-36751 MEDIUM
ENC DataVault < 7.2.3 - Ciphertext Malleability via Missing Integrity Check
CVSS 4.2
CVE-2021-45419 HIGH
Starcharge Titan 180 Premium <1.3.0.0.6 & Nova 360 <=1.3.0.0.7b102 - Input Validation Flaw
CVSS 8.8
CVE-2021-37188 HIGH
Digi TransPort DR64, VC74, WR11, WR11 XT, WR21, WR31, WR41, WR44 Firmware Authenticated Tampering
CVSS 8.8
CVE-2021-26103 MEDIUM
FortiProxy < 1.2.11 and FortiGate < 6.2.9, 6.4.6, 7.0.0 - Unauthenticated Cross-Site Request Forgery via SSL VPN Portal
CVSS 6.3
CVE-2021-26315 HIGH
AMD Epyc 7003 Firmware - Data Authenticity Bypass
CVSS 7.8
CVE-2021-43616 CRITICAL
npm 7.0.0-8.1.3 - Insufficient Verification of Data Authenticity in npm ci Command
CVSS 9.0
Details
Vulnerabilities 658