CWE-358

Improperly Implemented Security Check for Standard

Parent: CWE-573 - Improper Following of Specification by Caller

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

122 vulnerabilities with CWE-358
CVE-2024-27842 HIGH
macOS Sonoma <14.5 - Privilege Escalation
CVSS 7.8
CVE-2024-2617 HIGH
Hitachi Energy RTU500 CMU Firmware 13.2.1-13.2.6, 13.4.1-13.4.3, 13.5.1-13.5.2 - Authenticated Firmware Update Bypass
CVSS 7.2
CVE-2024-3845 MEDIUM
Google Chrome <124.0.6367.60 - CSRF
CVSS 4.3
CVE-2024-3844 MEDIUM
Google Chrome < 124.0.6367.60 - UI Spoofing via Crafted Chrome Extension
CVSS 4.3
CVE-2024-3838 MEDIUM
Google Chrome < 124.0.6367.60 - UI Spoofing via Autofill
CVSS 5.5
CVE-2024-25545 HIGH
Weave Desktop 7.78.10-7.84.1 - Local Code Execution via nwjs Framework Script Injection
CVSS 7.8
CVE-2024-23592 MEDIUM
Lenovo Synaptics Fingerprint Readers - Authentication Bypass via Fingerprint Replay
CVSS 6.3
CVE-2024-2174 HIGH
Google Chrome <122.0.6261.111 - Heap Corruption
CVSS 8.8
CVE-2023-2585 LOW
Keycloak - Auth Bypass
CVSS 3.5
CVE-2023-40445 HIGH
iPadOS 17.0 - Improperly Implemented Security Check for Standard
CVSS 7.5
CVE-2023-4501 CRITICAL
OpenText (Micro Focus) Visual COBOL <9.0 - Auth Bypass
CVSS 9.8
CVE-2023-3266 CRITICAL
CypberPower PowerPanel Enterprise - Auth Bypass
CVSS 9.8
CVE-2023-39403 CRITICAL
Huawei EMUI and HarmonyOS - Improper Authorization in installd Module
CVSS 9.1
CVE-2023-28601 HIGH
Zoom for Windows <5.14.0 - Memory Corruption
CVSS 8.3
CVE-2023-28113 MEDIUM
russh <0.36.2-0.37.1 - Info Disclosure
CVSS 5.9
CVE-2023-22393 HIGH
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 7.5
CVE-2022-38732 HIGH
SnapCenter < 4.7 - Missing Content Security Policy
CVSS 7.5
CVE-2022-2324 HIGH
SonicWall Hosted Email Security <10.0.17.7319 - Info Disclosure
CVSS 7.5
CVE-2022-27220 MEDIUM
SINEMA Remote Connect Server < V3.0 SP2 - Info Disclosure
CVSS 4.3
CVE-2022-27219 MEDIUM
SINEMA Remote Connect Server < V3.0 SP2 - Info Disclosure
CVSS 4.3
CVE-2022-25152 CRITICAL
ITarian < 6.35.37347.20040 - Authenticated Arbitrary Code Execution via Procedure Approval Bypass
CVSS 9.9
CVE-2022-22156 MEDIUM
Juniper Networks Junos OS - Privilege Escalation
CVSS 6.5
CVE-2021-26105 MEDIUM
FortiSandbox <= 3.1.4 and <= 3.2.2 - Authenticated Stack-Based Buffer Overflow via Profile Parser
CVSS 6.8
CVE-2021-26328 MEDIUM
AMD EPYC 7003 Series Firmware < milanpi_1.0.0.8 - Memory Integrity Loss via SNP_INIT Execution Mode Check Bypass
CVSS 4.4
CVE-2021-42017 MEDIUM
Siemens RUGGEDCOM ROS - Improper Certificate Validation via CBC Encryption Mode
CVSS 5.9
Details
Vulnerabilities 122