CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

157 vulnerabilities with CWE-354
CVE-2021-3772 MEDIUM
Linux SCTP - DoS
CVSS 6.5
CVE-2021-41067 HIGH
Listary <6 - Info Disclosure
CVSS 7.5
CVE-2021-41206 HIGH
TensorFlow - Memory Corruption
CVSS 7.0
CVE-2021-22276 MEDIUM
ABB System Access Point 2.0 Firmware < 2.6.4 - Information Disclosure
CVSS 6.1
CVE-2021-22442 HIGH
Huawei Smartphone - Info Disclosure
CVSS 7.5
CVE-2021-25388 HIGH
Knox Core <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 7.1
CVE-2021-31913 HIGH
JetBrains TeamCity <2020.2.3 - Open Redirect
CVSS 7.5
CVE-2021-20709 HIGH
NEC Aterm WF1200CR <1.3.2 - RCE
CVSS 7.2
CVE-2021-20184 MEDIUM
Moodle <3.10.1, <3.9.4, <3.8.7 - Info Disclosure
CVSS 4.3
CVE-2020-9210 MEDIUM
Huawei - Info Disclosure
CVSS 6.8
CVE-2020-14120 HIGH
Xiaomi - Privilege Escalation
CVSS 8.8
CVE-2020-4610 HIGH
IBM Security Secret Server - Code Injection
CVSS 7.8
CVE-2020-26141 MEDIUM
ALFA Windows 10 driver <6.1316.1209 - Info Disclosure
CVSS 6.5
CVE-2020-14009 MEDIUM
Proofpoint Enterprise Protection <8.16.4 - Info Disclosure
CVSS 6.3
CVE-2020-9118 MEDIUM
Huawei Sound X - Code Injection
CVSS 6.8
CVE-2020-25758 HIGH
D-Link DSR-250 <3.17 - Code Injection
CVSS 8.8
CVE-2020-5637 MEDIUM
Aterm SA3500G <3.5.9 - Code Injection
CVSS 6.8
CVE-2020-5798 HIGH
inSync Client <6.8.0 - Privilege Escalation
CVSS 7.8
CVE-2020-28656 MEDIUM
Volkswagen Polo 2019 - RCE
CVSS 6.8
CVE-2020-26896 HIGH
LND <0.11.0-beta - Info Disclosure
CVSS 8.2
CVE-2020-26895 MEDIUM
LND <0.10.0-beta - Privilege Escalation
CVSS 5.3
CVE-2020-25862 HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - DoS
CVSS 7.5
CVE-2020-7807 MEDIUM
LGPCSuite_Setup <1.0.0.3 - Code Injection
CVSS 5.6
CVE-2020-11497 HIGH
NAB Transact <2.1.0 - Auth Bypass
CVSS 7.5
CVE-2020-7810 HIGH
hslogin2.dll - RCE
CVSS 8.8
Details
Vulnerabilities 157
Exploit Likelihood Medium