CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

157 vulnerabilities with CWE-354
CVE-2020-13847 HIGH
Sylabs Singularity <3.6 - Info Disclosure
CVSS 7.5
CVE-2020-13845 HIGH
Sylabs Singularity 3.0-3.5 - Improper Validation
CVSS 7.5
CVE-2020-1834 MEDIUM
HUAWEI P30/HUAWEI P30 Pro <10.1.0.135(C00E135R2P11/P8) - Code Injec...
CVSS 4.6
CVE-2020-6228 HIGH
SAP Business Client <7.0 - Info Disclosure
CVSS 7.5
CVE-2020-1802 MEDIUM
OSCA-550 <1.0.1.23 - Info Disclosure
CVSS 4.6
CVE-2020-8838 MEDIUM
Zoho ManageEngine AssetExplorer 6.5 - RCE
CVSS 6.4
CVE-2020-1879 LOW
Huawei <versions> - Info Disclosure
CVSS 3.9
CVE-2019-5272 MEDIUM
USG9500 <V500R001C30;V500R001C60 - Privilege Escalation
CVSS 4.9
CVE-2019-18672 HIGH
ShapeShift KeepKey <6.2.2 - Info Disclosure
CVSS 7.5
CVE-2019-13496 HIGH
One Identity Cloud Access Manager <8.1.4 - Auth Bypass
CVSS 8.1
CVE-2019-1166 MEDIUM
Microsoft Windows - Info Disclosure
CVSS 5.9
CVE-2019-0071 HIGH
Junos OS - Privilege Escalation
CVSS 7.8
CVE-2019-11753 HIGH
Firefox - Privilege Escalation
CVSS 7.8
CVE-2019-1163 MEDIUM
Windows - Code Injection
CVSS 5.5
CVE-2019-10155 LOW
Libreswan <3.29 - Info Disclosure
CVSS 3.1
CVE-2019-12097 HIGH
Telerik Fiddler <5.0.20182.28034 - Code Injection
CVSS 7.8
CVE-2018-21070 HIGH
Samsung N/O - Privilege Escalation
CVSS 8.4
CVE-2018-6336 HIGH
Linuxfoundation Osquery < 3.2.7 - Security Feature Bypass
CVSS 7.8
CVE-2018-1000159 MEDIUM
tlslite-ng <0.7.3 - Improper Validation of Integrity Check Value
CVSS 5.9
CVE-2018-5382 MEDIUM
Bouncy Castle <1.47 - Integrity Compromise
CVSS 4.4
CVE-2018-5441 HIGH
PHOENIX CONTACT mGuard <8.6.0 - Info Disclosure
CVSS 7.8
CVE-2017-18689 HIGH
Samsung M(6.0)-N(7.0) - Auth Bypass
CVSS 7.5
CVE-2017-18649 HIGH
Samsung N(7.x) - Privilege Escalation
CVSS 7.2
CVE-2017-3224 HIGH
Quagga - Denial of Service
CVSS 8.2
CVE-2017-15994 CRITICAL
rsync 3.1.3-development - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 157
Exploit Likelihood Medium