CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2023-45150 MEDIUM
Nextcloud Calendar < 4.4.4 - Denial of Service via Email Address Validation
CVSS 4.3
CVE-2023-4929 MEDIUM
NPort 5000 Series - Improper Validation
CVSS 6.5
CVE-2023-20233 MEDIUM
Cisco IOS XR < 7.5.4 - Unauthenticated Denial of Service via Crafted Continuity Check Messages
CVSS 4.3
CVE-2023-38802 HIGH
FRRouting 7.5.1-9.0 - Denial of Service via Corrupted BGP Tunnel Encapsulation Attribute
CVSS 7.5
CVE-2023-2975 MEDIUM
OpenSSL 3.0.0-3.0.8 - Improper Authentication in AES-SIV Cipher
CVSS 5.3
CVE-2023-33668 CRITICAL
DigiExam < 14.0.2 - Unauthenticated Account Takeover via Native Module Integrity Check Bypass
CVSS 9.8
CVE-2023-36537 HIGH
Zoom Rooms for Windows <5.14.5 - Privilege Escalation
CVSS 7.3
CVE-2023-30673 MEDIUM
Smart Switch PC <4.3.23052_1 - Path Traversal
CVSS 5.5
CVE-2023-34459 MEDIUM
OpenZeppelin Contracts <4.9.2 - Code Injection
CVSS 5.3
CVE-2023-31439 MEDIUM
systemd 253 - Log File Integrity Check Bypass via Sealed Log Manipulation
CVSS 5.3
CVE-2023-31438 MEDIUM
systemd 253 - Log File Integrity Check Bypass via Truncation
CVSS 5.3
CVE-2023-31437 MEDIUM
systemd 253 - Log File Tampering via Sealed Log Manipulation
CVSS 5.3
CVE-2023-33981 MEDIUM
Briar < 1.4.22 - Message Spoofing via Integrity Check Bypass
CVSS 6.5
CVE-2023-28386 HIGH
Snap One OvrC Pro <7.2 - Code Execution
CVSS 8.6
CVE-2023-30356 HIGH
Shenzen Tenda Technology IP Camera CP3 <V11.10.00.2211041355 - Code...
CVSS 7.5
CVE-2023-23120 MEDIUM
TRENDnet TV-IP651WI <v1.07.01 - Code Injection
CVSS 5.9
CVE-2023-23119 MEDIUM
Ubiquiti airFiber AF2X Radio <3.2.2 - Info Disclosure
CVSS 5.9
CVE-2022-24404 MEDIUM
midnightblue tetra - Missing Cryptographic Integrity Check for Air-Interface Encrypted Traffic
CVSS 5.9
CVE-2022-45142 HIGH
Heimdal - Improper Validation of Integrity Check Value in GSSAPI ArcFour
CVSS 7.5
CVE-2022-45191 MEDIUM
Microchip RN4870 1.43 - Denial of Service via BLE Pair Confirm Message
CVSS 6.5
CVE-2022-46402 MEDIUM
Microchip RN4870 <1.43 - Buffer Overflow
CVSS 6.5
CVE-2022-36360 HIGH
Siemens LOGO! 8 BM Firmware <8.3 - Insufficient Firmware Update Authenticity Verification
CVSS 7.5
CVE-2022-38956 MEDIUM
Netgear WPN824EXT Firmware < 1.1.1_1.1.9 - Firmware Downgrade via MITM Attack
CVSS 5.3
CVE-2022-38955 HIGH
Netgear WPN824EXT WiFi Range Extender - MITM
CVSS 7.5
CVE-2022-36174 HIGH
FreshService <2.11.0, <4.2.0, <3.3.0 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 171
Exploit Likelihood Medium