CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

171 vulnerabilities with CWE-354
CVE-2020-4610 HIGH
IBM Security Secret Server - Code Injection
CVSS 7.8
CVE-2020-26141 MEDIUM
ALFA Windows 10 driver <6.1316.1209 - Info Disclosure
CVSS 6.5
CVE-2020-14009 MEDIUM
Proofpoint Enterprise Protection <8.16.4 - Info Disclosure
CVSS 6.3
CVE-2020-9118 MEDIUM
Huawei Sound X AIS-BW80H-00 Firmware - Insufficient Integrity Check for Software Packages
CVSS 6.8
CVE-2020-25758 HIGH
D-Link DSR-250 <3.17 - Code Injection
CVSS 8.8
CVE-2020-5637 MEDIUM
Aterm SA3500G <3.5.9 - Code Injection
CVSS 6.8
CVE-2020-5798 HIGH
inSync Client <6.8.0 - Privilege Escalation
CVSS 7.8
CVE-2020-28656 MEDIUM
Volkswagen Polo 2019 Discover Media - Arbitrary Code Execution via Unsigned Metainfo File Parsing
CVSS 6.8
CVE-2020-26896 HIGH
Lightning Network Daemon < 0.11.0 - Improper Validation of Integrity Check Value in Invoice Database
CVSS 8.2
CVE-2020-26895 MEDIUM
LND <0.10.0-beta - Privilege Escalation
CVSS 5.3
CVE-2020-25862 HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - DoS
CVSS 7.5
CVE-2020-7807 MEDIUM
LGPCSuite_Setup <1.0.0.3 - Code Injection
CVSS 5.6
CVE-2020-11497 HIGH
NAB Transact WooCommerce Extension 2.1.0 - Payment Bypass via Arbitrary Transaction ID
CVSS 7.5
CVE-2020-7810 HIGH
HandySoft hslogin2.dll - Remote File Download and Execution via ActiveX Method
CVSS 8.8
CVE-2020-13847 HIGH
Sylabs Singularity <3.6 - Info Disclosure
CVSS 7.5
CVE-2020-13845 HIGH
Sylabs Singularity 3.0-3.5 - Improper Validation
CVSS 7.5
CVE-2020-1834 MEDIUM
HUAWEI P30/HUAWEI P30 Pro <10.1.0.135(C00E135R2P11/P8) - Code Injec...
CVSS 4.6
CVE-2020-6228 HIGH
SAP Business Client <7.0 - Info Disclosure
CVSS 7.5
CVE-2020-1802 MEDIUM
OSCA-550 <1.0.1.23 - Info Disclosure
CVSS 4.6
CVE-2020-8838 MEDIUM
Zoho ManageEngine AssetExplorer 6.5 - RCE
CVSS 6.4
CVE-2020-1879 LOW
Huawei <versions> - Info Disclosure
CVSS 3.9
CVE-2019-5272 MEDIUM
USG9500 <V500R001C30;V500R001C60 - Privilege Escalation
CVSS 4.9
CVE-2019-18672 HIGH
ShapeShift KeepKey <6.2.2 - Info Disclosure
CVSS 7.5
CVE-2019-13496 HIGH
One Identity Cloud Access Manager <8.1.4 - Auth Bypass
CVSS 8.1
CVE-2019-1166 MEDIUM
Microsoft Windows - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 171
Exploit Likelihood Medium