CWE-358

Improperly Implemented Security Check for Standard

Parent: CWE-573 - Improper Following of Specification by Caller

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

132 vulnerabilities with CWE-358
CVE-2023-22393 HIGH
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 7.5
CVE-2022-38732 HIGH
SnapCenter < 4.7 - Missing Content Security Policy
CVSS 7.5
CVE-2022-2324 HIGH
SonicWall Hosted Email Security <10.0.17.7319 - Info Disclosure
CVSS 7.5
CVE-2022-27220 MEDIUM
SINEMA Remote Connect Server < V3.0 SP2 - Info Disclosure
CVSS 4.3
CVE-2022-27219 MEDIUM
SINEMA Remote Connect Server < V3.0 SP2 - Info Disclosure
CVSS 4.3
CVE-2022-25152 CRITICAL
ITarian < 6.35.37347.20040 - Authenticated Arbitrary Code Execution via Procedure Approval Bypass
CVSS 9.9
CVE-2022-22156 MEDIUM
Juniper Networks Junos OS - Privilege Escalation
CVSS 6.5
CVE-2021-26105 MEDIUM
FortiSandbox <= 3.1.4 and <= 3.2.2 - Authenticated Stack-Based Buffer Overflow via Profile Parser
CVSS 6.8
CVE-2021-26328 MEDIUM
AMD EPYC 7003 Series Firmware < milanpi_1.0.0.8 - Memory Integrity Loss via SNP_INIT Execution Mode Check Bypass
CVSS 4.4
CVE-2021-42017 MEDIUM
Siemens RUGGEDCOM ROS - Improper Certificate Validation via CBC Encryption Mode
CVSS 5.9
CVE-2021-34791 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated NAT ALG Security Bypass
CVSS 4.7
CVE-2021-34790 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated NAT ALG Security Bypass
CVSS 4.7
CVE-2021-31375 HIGH
Juniper Networks Junos OS <12.3R12-S18, <15.1R7-S9, <17.2 - RPKI Po...
CVSS 7.2
CVE-2021-3448 MEDIUM
dnsmasq < 2.85 - DNS Cache Poisoning via Fixed Port Query Forwarding
CVSS 4.0
CVE-2021-21387 HIGH
Wrongthink <2.3.0 - Info Disclosure
CVSS 8.1
CVE-2020-9295 MEDIUM
Fortinet Antivirus Engine < 6.00145 - Malformed RAR Archive Detection Bypass
CVSS 4.7
CVE-2020-10743 MEDIUM
OpenShift Container Platform - CSRF
CVSS 4.3
CVE-2020-1761 MEDIUM
OpenShift <console-4 - Info Disclosure
CVSS 6.1
CVE-2020-25686 LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Birthday Attack
CVSS 3.7
CVE-2020-25684 LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Insufficient Query Attribute Matching
CVSS 3.7
CVE-2020-8352 LOW
Lenovo Desktop Models - BIOS Configuration Change Detection Bypass
CVSS 2.4
CVE-2020-1728 MEDIUM
Keycloak < 10.0.0 - Missing HTTP Security Headers in Admin Console
CVSS 4.8
CVE-2020-7251 MEDIUM
McAfee ENS <10.6.1 - Info Disclosure
CVSS 5.0
CVE-2019-14823 HIGH
JSS CryptoManager >4.4.6-4.6.0 - Privilege Escalation
CVSS 7.4
CVE-2019-6742 CRITICAL
Samsung Galaxy S9 Firmware < 1.4.20.2 - Unauthenticated Remote Code Execution via GameServiceReceiver Update Mechanism
CVSS 9.8
Details
Vulnerabilities 132