CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2020-3220 MEDIUM
Cisco IOS XE - Unauthenticated Denial of Service via ESP Packet Tampering
CVSS 6.8
CVE-2020-10751 MEDIUM
Linux kernel <5.7 - Privilege Escalation
CVSS 6.1
CVE-2020-6081 HIGH
CODESYS Runtime 3.5.14.30 - Remote Code Execution via PLC_Task Network Request
CVSS 8.8
CVE-2020-7487 CRITICAL
EcoStruxure Machine Expert - Insufficient Verification of Data Authenticity
CVSS 9.8
CVE-2020-6443 HIGH
Google Chrome < 81.0.4044.92 - Remote Code Execution via Developer Tools
CVSS 8.8
CVE-2020-10266 HIGH
Universal Robots UR+ - Missing Integrity Check for Installed Components
CVSS 8.1
CVE-2020-11470 LOW
Zoom Meetings < 4.6.8 - Unauthenticated Microphone and Camera Access via Crafted Library Loading
CVSS 3.3
CVE-2020-10831 HIGH
Samsung Mobile Devices <10.0 - Privilege Escalation
CVSS 7.5
CVE-2020-7982 HIGH
OpenWrt 18.06.0-18.06.6, 19.07.0 & LEDE 17.01.0-17.01.7 - RCE via Opkg Checksum Bypass
CVSS 8.1
CVE-2020-8660 MEDIUM
Envoy < 1.12.3 - TLS Inspector Bypass via TLS 1.3
CVSS 5.3
CVE-2020-3174 MEDIUM
Cisco NX-OS - Unauthenticated ARP Cache Poisoning via Gratuitous ARP Request
CVSS 4.7
CVE-2019-8921 MEDIUM
bluez < 5.48 - Information Disclosure via SVC_ATTR_REQ Handling
CVSS 6.5
CVE-2019-16007 HIGH
Cisco AnyConnect Secure Mobility Client for Android - DoS
CVSS 7.1
CVE-2019-16000 MEDIUM
Cisco Umbrella Roaming Client for Windows - Privilege Escalation
CVSS 4.4
CVE-2019-19160 MEDIUM
Reportexpress ProPlus < 3.0.0.62 - Remote Code Execution via VBScript in Configure File
CVSS 5.7
CVE-2019-11480 HIGH
c-kernel < 2019-07-16 - Unauthenticated Package Installation via Hardcoded Insecure APT Options
CVSS 8.4
CVE-2019-1866 LOW
Cisco Webex Business Suite <39.1.0 - SSRF
CVSS 3.1
CVE-2019-18905 MEDIUM
SUSE Linux Enterprise Server <12,15 - Info Disclosure
CVSS 4.8
CVE-2019-20530 CRITICAL
Samsung Android N(7.1)-Q(10.0) - Arbitrary Code Execution on Lock Screen
CVSS 9.8
CVE-2019-17654 HIGH
FortiManager <= 6.0.6 - Unauthenticated Cross-Site WebSocket Hijacking
CVSS 8.8
CVE-2019-5161 CRITICAL
WAGO PFC200 Firmware - Remote Code Execution via Crafted XML File
CVSS 9.1
CVE-2019-17636 HIGH
Eclipse Theia 0.3.9-0.15.0 - Unauthenticated Arbitrary File Read via Mini-Browser HTTP Endpoint
CVSS 8.1
CVE-2019-17228 MEDIUM
Motors - Car Dealer, Classifieds & Listing < 1.4.0 - Unauthenticated Options Change via options.php
CVSS 6.5
CVE-2019-12510 CRITICAL
NETGEAR Nighthawk X10-R900 < 1.0.4.26 - Unauthenticated Authentication Bypass via X-Forwarded-For Header
CVSS 9.1
CVE-2019-5613 CRITICAL
FreeBSD 12.0-RELEASE - Insufficient Verification of Data Authenticity in IPsec Packet Processor
CVSS 9.8
Details
Vulnerabilities 658