CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

200 vulnerabilities with CWE-494
CVE-2023-39474 HIGH
Inductiveautomation Ignition - Download Without Integrity Check
CVSS 8.8
CVE-2023-47353 HIGH
Imoulife Imou GO - Download Without Integrity Check
CVSS 8.8
CVE-2023-5592 HIGH
Phoenixcontact Multiprog - Download Without Integrity Check
CVSS 7.5
CVE-2023-46144 MEDIUM
PLCnext - Info Disclosure
CVSS 6.5
CVE-2023-46143 HIGH
PHOENIX CONTACT classic line PLC - RCE
CVSS 7.5
CVE-2023-5630 MEDIUM
Schneider-electric Eb450 Firmware - Download Without Integrity Check
CVSS 6.5
CVE-2023-45842 HIGH
Buildroot - Download Without Integrity Check
CVSS 8.1
CVE-2023-45841 HIGH
Buildroot - Download Without Integrity Check
CVSS 8.1
CVE-2023-45840 HIGH
Buildroot - Download Without Integrity Check
CVSS 8.1
CVE-2023-45839 HIGH
Buildroot - Download Without Integrity Check
CVSS 8.1
CVE-2023-45838 HIGH
Buildroot - Download Without Integrity Check
CVSS 8.1
CVE-2023-43608 HIGH
Buildroot <2023.08.1 - RCE
CVSS 8.1
CVE-2023-46887 HIGH
Dreamer CMS <4.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-5984 HIGH
Schneider-electric Ion8650 Firmware - Download Without Integrity Check
CVSS 7.2
CVE-2023-45799 HIGH
Mlsoft Tco!stream < 8.0.23.215 - Download Without Integrity Check
CVSS 7.2
CVE-2023-45821 MEDIUM
Hub < 1.16.0 - Download Without Integrity Check
CVSS 5.4
CVE-2023-37220 HIGH
Synel Synergy/a Firmware < 3015.1 - Download Without Integrity Check
CVSS 7.2
CVE-2023-4041 CRITICAL
Silicon Labs Gecko Bootloader - Classic Buffer Overflow
CVSS 9.8
CVE-2023-40254 HIGH
Genians Genian Nac < 4.0.156 - SQL Injection
CVSS 7.5
CVE-2023-37864 HIGH
Phoenixcontact WP 6070-wvps Firmware < 4.0.10 - Download Without Integrity Check
CVSS 7.2
CVE-2023-29401 MEDIUM
Context.FileAttachment - Info Disclosure
CVSS 4.3
CVE-2023-28317 MEDIUM
Rocket.chat - Improper Authorization
CVSS 5.3
CVE-2023-24503 HIGH
Electra Central AC unit - Privilege Escalation
CVSS 7.5
CVE-2023-24500 HIGH
Electra Central AC unit - Privilege Escalation
CVSS 7.5
CVE-2023-22635 HIGH
Fortinet Forticlient < 5.6.6 - Download Without Integrity Check
CVSS 7.3
Details
Vulnerabilities 200
Exploit Likelihood Medium