CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2024-49406 MEDIUM
Blockchain Keystore <1.3.16 - Privilege Escalation
CVSS 6.7
CVE-2024-47255 MEDIUM
2N Access Commander <3.1.1.2 - Privilege Escalation
CVSS 4.7
CVE-2024-49875 MEDIUM
Linux Kernel - Denial of Service via NFS EBADMSG Error Handling
CVSS 5.5
CVE-2024-48930 HIGH
secp256k1-node <5.0.1-3.8.1 - Info Disclosure
CVE-2024-47089 MEDIUM
Apex Softcell LD Geo - Privilege Escalation
CVSS 6.5
CVE-2024-45789 MEDIUM
Reedos aiM-Star 2.0.1 - Authenticated Registration Constraint Bypass via Mode Parameter
CVSS 4.3
CVE-2024-41909 MEDIUM
Apache MINA SSHD < 2.12.0 - Security Feature Downgrade via Terrapin Attack
CVSS 5.9
CVE-2024-3596 CRITICAL
FreeRADIUS < 3.0.27 - RADIUS Response Forgery via MD5 Chosen-Prefix Collision
CVSS 9.0
CVE-2024-31958 MEDIUM
Samsung Mobile Processor - Memory Corruption
CVSS 6.8
CVE-2024-34714 HIGH
hoppscotch-extension >= 0.28 < 0.35 - Improper Origin Validation
CVSS 7.6
CVE-2024-3727 HIGH
containers/image < 5.30.1 - Improper Validation of Integrity Check Value
CVSS 8.3
CVE-2024-23462 LOW
Zscaler Client Connector <3.4 - DoS
CVSS 3.3
CVE-2024-23461 MEDIUM
Zscaler Client Connector <3.4 - RCE
CVSS 4.2
CVE-2024-32883 HIGH
MCUboot <= 1.11.0 - Improper Validation of Integrity Check Value in TLV Structure
CVSS 7.7
CVE-2024-25678 CRITICAL
LiteSpeed QUIC <4.0.4 - Info Disclosure
CVSS 9.8
CVE-2024-23790 LOW
OTRS <7.0.48-8.0.37-2023.1.1 - Info Disclosure
CVSS 3.5
CVE-2023-50738 MEDIUM
Lexmark Printer Firmware <230.041, 230.075-230.086, 230.100-230.104, 230.200-230.209 - Firmware Downgrade Bypass
CVSS 4.3
CVE-2023-33206 MEDIUM
Diebold Nixdorf VSS <4.3.0 - Info Disclosure
CVSS 6.8
CVE-2023-24063 MEDIUM
Diebold Nixdorf VSS <3.3.0 SR10 - Info Disclosure
CVSS 6.8
CVE-2023-41970 MEDIUM
Zscaler Client Connector <4.1.0.62 - RCE
CVSS 6.0
CVE-2023-42143 MEDIUM
Shelly TRV Firmware 20220811-152343/v2.1.8@5afc928c - Missing Integrity Check
CVSS 5.4
CVE-2023-48795 MEDIUM
OpenSSH <9.6 - Open Redirect
CVSS 5.9
CVE-2023-36650 HIGH
ProLion CryptoSpike 3.0.15P2 - Command Injection
CVSS 7.2
CVE-2023-28802 MEDIUM
Zscaler Client Connector <4.2.0.149 - Privilege Escalation
CVSS 4.9
CVE-2023-28002 MEDIUM
FortiOS <7.2.3, <7.0.12, all 6.x - Code Injection
CVSS 6.4
Details
Vulnerabilities 171
Exploit Likelihood Medium