CWE-345— Insufficient Verification of Data Authenticity
406 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 1 of 9
- CVE-2013-2167CRITICALCVSS 9.8EG 9.82019-12-10
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
- CVE-2015-3956CRITICALCVSS 9.82019-03-25
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unauthorized configurat…
- CVE-2015-5236HIGHCVSS 7.5EG 7.52022-07-07
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin,…
- CVE-2015-8371HIGHCVSS 8.8EG 8.82023-09-21
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached.…
- CVE-2016-1000004CRITICALCVSS 9.8EG 9.82020-02-19
Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versio…
- CVE-2017-1405MEDIUMCVSS 4.42018-06-08
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392.
- CVE-2017-17023HIGHCVSS 8.12019-04-09
The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerabi…
- CVE-2017-1773MEDIUMCVSS 4.0EG 4.02018-01-31
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
- CVE-2017-20180MEDIUMCVSS 4.6EG 7.52023-03-06
A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinSpend of the file CoinSpend.cpp of the component Proof Handler. The manipulation leads to insufficient verification of d…
- CVE-2017-2667HIGHCVSS 8.12018-03-12
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-i…
- CVE-2017-3198CRITICALCVSS 9.82018-07-09
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without …
- CVE-2017-3224HIGHCVSS 8.22018-07-24
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is det…
- CVE-2018-10080HIGHCVSS 8.62018-04-13
Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.
- CVE-2018-10626MEDIUMCVSS 4.4EG 4.42018-08-10
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device informati…
- CVE-2018-10894MEDIUMCVSS 5.42018-08-01
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
- CVE-2018-12333HIGHCVSS 8.12018-06-17
Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code.
- CVE-2018-15801HIGHCVSS 7.42018-12-19
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWT…
- CVE-2018-17287MEDIUMCVSS 4.92019-04-18
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by a…
- CVE-2018-17938MEDIUMCVSS 5.32018-10-03
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
- CVE-2018-19971CRITICALCVSS 9.82019-04-16
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
- CVE-2018-2434MEDIUMCVSS 4.32018-07-10
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decouple…
- CVE-2018-6562HIGHCVSS 7.52018-05-18
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.
- CVE-2018-7798HIGHCVSS 8.22018-11-02
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.
- CVE-2018-7932HIGHCVSS 8.82018-04-24
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, whi…
- CVE-2019-0379MEDIUMCVSS 5.3EG 5.32019-10-08
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check
- CVE-2019-0805HIGHCVSS 7.82019-04-09
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-079…
- CVE-2019-1000012HIGHCVSS 8.82019-02-04
Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitabl…
- CVE-2019-1000013HIGHCVSS 8.82019-02-04
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be explo…
- CVE-2019-10157MEDIUMCVSS 4.7EG 4.72019-06-12
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token se…
- CVE-2019-10181HIGHCVSS 8.1EG 8.12019-07-31
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code…
- CVE-2019-10492HIGHCVSS 7.8EG 7.82019-09-30
Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 820, S…
- CVE-2019-10943HIGHCVSS 7.5EG 7.52019-08-13
A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS var…
- CVE-2019-11235CRITICALCVSS 9.82019-04-22
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a…
- CVE-2019-11480HIGHCVSS 8.4EG 8.42020-04-14
The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options when creating the build chroot environment. This could allow an attacker who is able to perform a MITM attack between the …
- CVE-2019-11737MEDIUMCVSS 5.3EG 5.32019-09-27
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability a…
- CVE-2019-12504HIGHCVSS 8.8EG 8.82019-06-07
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to instal…
- CVE-2019-12510CRITICALCVSS 9.1EG 9.12020-02-24
In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (…
- CVE-2019-12620MEDIUMCVSS 5.3EG 5.32019-09-18
A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for …
- CVE-2019-12804MEDIUMCVSS 5.5EG 5.52019-07-10
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.
- CVE-2019-13483HIGHCVSS 7.3EG 7.32019-07-25
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
- CVE-2019-15162MEDIUMCVSS 5.3EG 5.32019-10-03
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
- CVE-2019-15613HIGHCVSS 8.0EG 8.02020-02-04
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
- CVE-2019-15971MEDIUMCVSS 4.3EG 4.32019-11-26
A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to …
- CVE-2019-16000MEDIUMCVSS 4.4EG 4.42020-09-23
A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insuf…
- CVE-2019-16007HIGHCVSS 7.1EG 7.12020-09-23
A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service …
- CVE-2019-16398MEDIUMCVSS 6.8EG 6.82019-09-19
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
- CVE-2019-1667LOWCVSS 3.32019-02-21
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization controls. An attac…
- CVE-2019-17006CRITICALCVSS 9.8EG 9.82020-10-22
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a…
- CVE-2019-17228MEDIUMCVSS 6.5EG 6.52020-02-24
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
- CVE-2019-17636HIGHCVSS 8.1EG 8.12020-03-10
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to …
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →