CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

596 vulnerabilities with CWE-345
CVE-2015-3956 CRITICAL
Hospira <13.4 - Unauthenticated RCE
CVSS 9.8
CVE-2015-9232 MEDIUM
Good for Enterprise 3.0.0.415 - Insufficient Verification of Data Authenticity in Authentication Delegation API
CVSS 5.3
CVE-2015-6854 CRITICAL
CA Single Sign-On R12.0 < SP3 CR13 / R12.5 < CR5 - DoS & Info Disclosure via Crafted Request
CVSS 9.1
CVE-2015-6853 CRITICAL
CA Single Sign-On Domino Web Agent - Denial of Service and Information Disclosure via Crafted Request
CVSS 9.1
CVE-2015-7539 HIGH
Jenkins < 1.640 and LTS < 1.625.2 - Unauthenticated Arbitrary Code Execution via Plugin Checksum Bypass
CVSS 7.5
CVE-2015-8254 MEDIUM
RSI Video Technologies Frontel Protocol < 2.0 - Unauthenticated Alarm Spoofing and Deactivation via MITM
CVSS 5.9
CVE-2015-2908
Mobile Devices C4 OBD-II Dongle Firmware < 3.4 - Remote Code Execution via Unvalidated Firmware Update
CVE-2015-3908
Ansible < 1.9.2 - Insufficient Verification of Data Authenticity in X.509 Certificate
CVE-2015-4674
TimeDoctor Pro 1.4.72.3 - Unauthenticated Remote Code Execution via Unsigned AutoUpdate
CVE-2015-0251
Apache Subversion 1.5.0-1.7.19 and 1.8.0-1.8.11 - Authenticated svn:author Property Spoofing via v1 HTTP Protocol
CVE-2015-0259
OpenStack Nova < 2014.1.4, 2014.2.x < 2014.2.3, kilo < kilo-3 - WebSocket Authentication Hijacking via Crafted Webpage
CVE-2014-5406
Hospira LifeCare PCA Infusion System < 7.0 - Unauthenticated Data Modification via Network Traffic
CVE-2014-8165
powerpc-utils - Remote Code Execution via Unsafe Pickle Deserialization
CVE-2014-9194
Arbiter 1094B GPS Substation Clock - DoS
CVE-2014-4936
Malwarebytes Anti-Malware <2.0.3 & MBAE <1.04.1.1012 - RCE
CVE-2014-4883
lwip < 1.4.1 - DNS Cache Poisoning via Predictable Query IDs and Source Ports
CVE-2014-2718
T-mobile Tm-ac1900 < 3.0.0.4.374.x - Data Authenticity Bypass
CVE-2014-0364
Ignite Realtime Smack XMPP API <4.0.0-rc1 - Info Disclosure
CVE-2013-2167 CRITICAL
python-keystoneclient 0.2.3-0.2.5 - Middleware Memcache Signing Bypass
CVSS 9.8
CVE-2013-7398
Async Http Client <1.9.0 - Man-in-the-Middle
CVE-2013-7397
Async Http Client <1.9.0 - Man-in-the-Middle
Details
Vulnerabilities 596