CWE-354— Improper Validation of Integrity Check Value
120 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-354page 1 of 3
- CVE-2012-1170HIGHCVSS 7.5EG 7.52019-11-14
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
- CVE-2016-15028MEDIUMCVSS 4.8EG 5.92023-03-12
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation l…
- CVE-2017-18649HIGHCVSS 7.2EG 7.22020-04-07
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system image, aka the "SamFA…
- CVE-2017-18689HIGHCVSS 7.5EG 7.52020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos5433, Exynos7420, or Exynos7870 chipsets) software. An attacker can bypass a ko (aka Kernel Module) signature by modifying the count of kernel modules. The Sam…
- CVE-2017-3224HIGHCVSS 8.22018-07-24
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is det…
- CVE-2018-1000159MEDIUMCVSS 5.92018-04-18
tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper Validation of Integrity Check Value vulnerability in TLS implementation, tlslite/utils/constanttime.py: ct_check_cbc_m…
- CVE-2018-21070HIGHCVSS 8.4EG 8.42020-04-08
An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity check. The Samsung ID …
- CVE-2018-5382MEDIUMCVSS 4.42018-04-16
The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. Thi…
- CVE-2018-5441HIGHCVSS 7.82018-01-30
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Ver…
- CVE-2018-6336HIGHCVSS 7.8EG 7.82018-12-31
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the…
- CVE-2019-0071HIGHCVSS 7.8EG 7.82019-10-09
Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in specific versions of Junos OS, affecting specific EX Series platforms, the Veriexec subsystem w…
- CVE-2019-10155LOWCVSS 3.1EG 3.12019-06-12
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integr…
- CVE-2019-1163MEDIUMCVSS 5.5EG 5.52019-08-14
A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the …
- CVE-2019-1166MEDIUMCVSS 5.9EG 5.92019-10-10
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
- CVE-2019-11753HIGHCVSS 7.8EG 7.82019-09-27
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotecte…
- CVE-2019-12097HIGHCVSS 7.82019-06-03
Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privilege escalation by replacing the original EnableLoopback.exe.
- CVE-2019-13496HIGHCVSS 8.1EG 8.12019-11-04
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.
- CVE-2019-18672HIGHCVSS 7.5EG 7.52019-12-06
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F f…
- CVE-2019-5272MEDIUMCVSS 4.9EG 4.92019-12-26
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifica…
- CVE-2020-11497HIGHCVSS 7.5EG 7.52020-08-26
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment…
- CVE-2020-13845HIGHCVSS 7.5EG 7.52020-07-14
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descripto…
- CVE-2020-13847HIGHCVSS 7.5EG 7.52020-07-14
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.
- CVE-2020-14009MEDIUMCVSS 6.3EG 6.32021-05-07
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists…
- CVE-2020-14120HIGHCVSS 8.8EG 8.82022-04-21
Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and…
- CVE-2020-1802MEDIUMCVSS 4.6EG 4.62020-04-10
There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently validate the integrity of certain file in certain loading processes, successful exploit could allow the attacker to load a cr…
- CVE-2020-1834MEDIUMCVSS 4.6EG 4.62020-06-18
HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's in…
- CVE-2020-1879LOWCVSS 3.9EG 3.92020-03-20
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected pr…
- CVE-2020-25758HIGHCVSS 8.8EG 8.82020-12-15
An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. Th…
- CVE-2020-25862HIGHCVSS 7.5EG 7.52020-10-06
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
- CVE-2020-26141MEDIUMCVSS 6.5EG 6.52021-05-11
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possib…
- CVE-2020-26895MEDIUMCVSS 5.3EG 5.32020-10-21
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless o…
- CVE-2020-26896HIGHCVSS 8.2EG 8.22020-10-21
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before re…
- CVE-2020-28656MEDIUMCVSS 6.8EG 6.82020-11-16
The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause …
- CVE-2020-4610HIGHCVSS 7.8EG 7.82021-06-25
IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919.
- CVE-2020-5637MEDIUMCVSS 6.8EG 6.82020-12-14
Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program.
- CVE-2020-5798HIGHCVSS 7.8EG 7.82020-12-07
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
- CVE-2020-5964HIGHCVSS 7.8EG 7.82020-06-25
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or info…
- CVE-2020-6228HIGHCVSS 7.5EG 7.52020-04-14
SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer.
- CVE-2020-7807MEDIUMCVSS 5.6EG 5.62020-09-14
A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerabilit…
- CVE-2020-7810HIGHCVSS 8.8EG 8.82020-08-07
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy fi…
- CVE-2020-8838MEDIUMCVSS 6.4EG 6.42020-03-23
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY…
- CVE-2020-9118MEDIUMCVSS 6.8EG 6.82021-02-06
There is an insufficient integrity check vulnerability in Huawei Sound X Product. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to…
- CVE-2020-9210MEDIUMCVSS 6.8EG 6.82024-12-27
There is an insufficient integrity vulnerability in Huawei products. A module does not perform sufficient integrity check in a specific scenario. Attackers can exploit the vulnerability by physically install malware. This could compromise …
- CVE-2021-1883MEDIUMCVSS 5.5EG 5.52021-09-08
This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted …
- CVE-2021-20184MEDIUMCVSS 4.3EG 4.32021-01-28
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
- CVE-2021-20709HIGHCVSS 7.2EG 7.22021-04-26
Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker with an admin…
- CVE-2021-22276MEDIUMCVSS 6.1EG 6.12021-09-23
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.
- CVE-2021-22442HIGHCVSS 7.5EG 7.52021-08-02
There is an Improper Validation of Integrity Check Value Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
- CVE-2021-25388HIGHCVSS 7.1EG 7.12021-06-11
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
- CVE-2021-31913HIGHCVSS 7.5EG 7.52021-05-11
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.
Map vulnerabilities like CWE-354 to your infrastructure
EchelonGraph correlates every CVE — across CWE-354 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →