CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

211 vulnerabilities with CWE-494
CVE-2023-37220 HIGH
Synel Synergy Terminals < 3015.1 - Unauthenticated Code Download Without Integrity Check
CVSS 7.2
CVE-2023-4041 CRITICAL
Silicon Labs Gecko Bootloader - Classic Buffer Overflow
CVSS 9.8
CVE-2023-40254 HIGH
Genian NAC 4.0.0-4.0.155, 5.0.0-5.0.42; Suite 5.0.0-5.0.54; ZTNA 6.0.0-6.0.15 - Code Download Without Integrity Check
CVSS 7.5
CVE-2023-37864 HIGH
Phoenixcontact WP 6070-wvps Firmware < 4.0.10 - Download Without Integrity Check
CVSS 7.2
CVE-2023-29401 MEDIUM
Context.FileAttachment - Info Disclosure
CVSS 4.3
CVE-2023-28317 MEDIUM
Rocket.Chat - Message Timestamp Manipulation via Edit Function
CVSS 5.3
CVE-2023-24503 HIGH
Electra Central AC unit - Privilege Escalation
CVSS 7.5
CVE-2023-24500 HIGH
Electra Central AC unit - Privilege Escalation
CVSS 7.5
CVE-2023-22635 HIGH
FortiClient 4.0.0-5.6.6 - Privilege Escalation via Installer Modification
CVSS 7.3
CVE-2023-27025 HIGH
RuoYi < 4.7.6 - Arbitrary File Download via Background Management Module
CVSS 7.5
CVE-2023-28818 MEDIUM
Veritas NetBackup IT Analytics <11.2.0 - Code Injection
CVSS 5.3
CVE-2023-27574 CRITICAL
ShadowsocksX-NG 1.10.0 - Download of Code Without Integrity Check
CVSS 9.8
CVE-2023-23110 HIGH
Netgear WNR612v2/DGN1000v3/D6100/WNR1000v2/XAVN2001v2/WNR2200/WNR2500/R8900/R9000 Firmware - Fixed Checksum Bypass
CVSS 7.4
CVE-2022-24117 CRITICAL
General Electric Renewable Energy - Info Disclosure
CVSS 9.8
CVE-2022-46430 MEDIUM
TP-Link TL-WR740N <v3.12.4 - Authenticated RCE/DoS
CVSS 4.8
CVE-2022-46428 MEDIUM
TP-Link TL-WR1043ND V1 <3.13.15 - Authenticated RCE/DoS
CVSS 4.8
CVE-2022-46423 HIGH
Netgear WNR2000v1 <1.2.3.7 - MITM/DoS
CVSS 8.1
CVE-2022-37908 MEDIUM
ArubaOS 6.5.4.0-6.5.4.21 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 - Authenticated Bootloader Integrity Compromise
CVSS 5.8
CVE-2022-4261 MEDIUM
Rapid7 InsightVM and Nexpose < 6.6.172 - Unauthenticated Code Execution via Malicious Update
CVSS 4.4
CVE-2022-40799 HIGH KEV
D-Link DNR-322L <= 2.60B15 - Authenticated Remote Code Execution via Backup Config
CVSS 8.8
CVE-2022-45442 HIGH
Sinatra 2.0-2.2.2 and 3.0-3.0.3 - Reflected File Download via User-Supplied Filename in Content-Disposition Header
CVSS 8.8
CVE-2022-38199 MEDIUM
Esri ArcGIS Server - Remote File Download
CVSS 6.1
CVE-2022-31324 MEDIUM
Penta Security Systems Inc WAPPLES <6.0 r3 4.10-hotfix1 - File Down...
CVSS 6.5
CVE-2022-36671 HIGH
Novel-Plus 3.6.2 - Arbitrary File Download via Background File Download API
CVSS 7.5
CVE-2022-36359 HIGH
Django 3.2-3.2.15 and 4.0-4.0.7 - Reflected File Download via User-Supplied Filename in FileResponse
CVSS 8.8
Details
Vulnerabilities 211
Exploit Likelihood Medium