CWE-354
Medium likelihoodImproper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
160 vulnerabilities with CWE-354
CVE-2024-23462
LOW
Zscaler Client Connector <3.4 - DoS
CVSS 3.3
CVE-2024-23461
MEDIUM
Zscaler Client Connector <3.4 - RCE
CVSS 4.2
CVE-2024-32883
HIGH
MCUboot <= 1.11.0 - Improper Validation of Integrity Check Value in TLV Structure
CVSS 7.7
CVE-2024-25678
CRITICAL
LiteSpeed QUIC <4.0.4 - Info Disclosure
CVSS 9.8
CVE-2024-23790
LOW
OTRS <7.0.48-8.0.37-2023.1.1 - Info Disclosure
CVSS 3.5
CVE-2023-50738
MEDIUM
Lexmark Printer Firmware <230.041, 230.075-230.086, 230.100-230.104, 230.200-230.209 - Firmware Downgrade Bypass
CVSS 4.3
CVE-2023-33206
MEDIUM
Diebold Nixdorf VSS <4.3.0 - Info Disclosure
CVSS 6.8
CVE-2023-24063
MEDIUM
Diebold Nixdorf VSS <3.3.0 SR10 - Info Disclosure
CVSS 6.8
CVE-2023-41970
MEDIUM
Zscaler Client Connector <4.1.0.62 - RCE
CVSS 6.0
CVE-2023-42143
MEDIUM
Shelly TRV Firmware 20220811-152343/v2.1.8@5afc928c - Missing Integrity Check
CVSS 5.4
CVE-2023-48795
MEDIUM
OpenSSH <9.6 - Open Redirect
CVSS 5.9
CVE-2023-36650
HIGH
ProLion CryptoSpike 3.0.15P2 - Command Injection
CVSS 7.2
CVE-2023-28802
MEDIUM
Zscaler Client Connector <4.2.0.149 - Privilege Escalation
CVSS 4.9
CVE-2023-28002
MEDIUM
FortiOS <7.2.3, <7.0.12, all 6.x - Code Injection
CVSS 6.4
CVE-2023-45150
MEDIUM
Nextcloud Calendar < 4.4.4 - Denial of Service via Email Address Validation
CVSS 4.3
CVE-2023-4929
MEDIUM
NPort 5000 Series - Improper Validation
CVSS 6.5
CVE-2023-20233
MEDIUM
Cisco IOS XR < 7.5.4 - Unauthenticated Denial of Service via Crafted Continuity Check Messages
CVSS 4.3
CVE-2023-38802
HIGH
FRRouting 7.5.1-9.0 - Denial of Service via Corrupted BGP Tunnel Encapsulation Attribute
CVSS 7.5
CVE-2023-2975
MEDIUM
OpenSSL 3.0.0-3.0.8 - Improper Authentication in AES-SIV Cipher
CVSS 5.3
CVE-2023-33668
CRITICAL
DigiExam < 14.0.2 - Unauthenticated Account Takeover via Native Module Integrity Check Bypass
CVSS 9.8
CVE-2023-36537
HIGH
Zoom Rooms for Windows <5.14.5 - Privilege Escalation
CVSS 7.3
CVE-2023-30673
MEDIUM
Smart Switch PC <4.3.23052_1 - Path Traversal
CVSS 5.5
CVE-2023-34459
MEDIUM
OpenZeppelin Contracts <4.9.2 - Code Injection
CVSS 5.3
CVE-2023-31439
MEDIUM
systemd 253 - Log File Integrity Check Bypass via Sealed Log Manipulation
CVSS 5.3
CVE-2023-31438
MEDIUM
systemd 253 - Log File Integrity Check Bypass via Truncation
CVSS 5.3
Details
Vulnerabilities
160
Exploit Likelihood
Medium