CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2022-39845 MEDIUM
Samsung Kies <2.6.4.22074 - Privilege Escalation
CVSS 5.5
CVE-2022-39844 MEDIUM
Smart Switch PC <4.3.22083 - Privilege Escalation
CVSS 5.5
CVE-2022-29549 HIGH
Qualys Cloud Agent for Linux < 2.5.548.2 - Privilege Escalation via Unchecked Program Execution
CVSS 7.3
CVE-2022-35961 HIGH
OpenZeppelin Contracts - Signature Malleability
CVSS 7.9
CVE-2022-30316 MEDIUM
Honeywell Experion PKS Safety Manager 5.02 - Unauthenticated Firmware Manipulation via Insecure Checksum Validation
CVSS 6.8
CVE-2022-33711 MEDIUM
Samsung USB Driver <1.7.56.0 - Path Traversal
CVSS 5.5
CVE-2022-21757 HIGH
Android - Denial of Service via Missing Count Check in WIFI Firmware
CVSS 7.5
CVE-2022-29898 CRITICAL
PHOENIX CONTACT RAD-ISM-900-EN-* - RCE
CVSS 9.1
CVE-2022-29173 HIGH
go-tuf < 0.3.0 - Improper Validation of Integrity Check Value
CVSS 8.0
CVE-2022-25946 HIGH
F5 BIG-IP Advanced WAF, ASM, and GC <9.0 - Auth Bypass
CVSS 8.7
CVE-2022-22781 HIGH
Zoom Client for Meetings <5.9.6 - Privilege Escalation
CVSS 7.5
CVE-2022-22253 HIGH
Huawei EMUI - Improper Validation of Integrity Check Value in DFX Module
CVSS 7.5
CVE-2021-37182 HIGH
Siemens SCALANCE XM408-4C/XM408-8C/XM416-4C/XR524-8C/XR526-8C <6.5 - Information Disclosure
CVSS 7.5
CVE-2021-4148 MEDIUM
Linux Kernel < 5.14.16 - Denial of Service via Missing Sanity Check in block_invalidatepage
CVSS 5.5
CVE-2021-3772 MEDIUM
Linux Kernel < 5.15.0 - Denial of Service via Spoofed SCTP Chunks
CVSS 6.5
CVE-2021-41067 HIGH
Listary < 6 - Unauthenticated Arbitrary Code Execution via MITM Update Package Tampering
CVSS 7.5
CVE-2021-41206 HIGH
TensorFlow 2.4.0-2.4.3, 2.6.0 - Missing Tensor Shape Validation Leading to Memory Corruption
CVSS 7.0
CVE-2021-22276 MEDIUM
ABB System Access Point Firmware < 2.6.4 - Unauthenticated Firmware Integrity Check Bypass
CVSS 6.1
CVE-2021-22442 HIGH
Huawei Smartphone - Info Disclosure
CVSS 7.5
CVE-2021-25388 HIGH
Knox Core <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 7.1
CVE-2021-31913 HIGH
JetBrains TeamCity <2020.2.3 - Open Redirect
CVSS 7.5
CVE-2021-20709 HIGH
NEC Aterm WF1200CR/WG1200CR/WG2600HS Firmware - Authenticated OS Command Injection via Crafted Request
CVSS 7.2
CVE-2021-20184 MEDIUM
Moodle <3.10.1, <3.9.4, <3.8.7 - Info Disclosure
CVSS 4.3
CVE-2020-9210 MEDIUM
Huawei Myna Firmware - Insufficient Integrity Check
CVSS 6.8
CVE-2020-14120 HIGH
MIUI - Privilege Escalation via Unchecked Third-Party Application Parameters
CVSS 8.8
Details
Vulnerabilities 171
Exploit Likelihood Medium