CWE-358— Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.— MITRE CWE catalog
138 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-358page 2 of 3
- CVE-2018-1243HIGHCVSS 7.5EG 7.52018-07-02
Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only sessi…
- CVE-2017-15107HIGHCVSS 7.5EG 7.52018-01-23
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
- CVE-2017-15665HIGHCVSS 7.5EG 7.52018-01-10
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
- CVE-2017-15664HIGHCVSS 7.5EG 7.52018-01-10
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121.
- CVE-2017-15663HIGHCVSS 7.5EG 7.52018-01-10
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
- CVE-2017-15662HIGHCVSS 7.5EG 7.52018-01-10
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123.
- CVE-2017-7177HIGHCVSS 7.5EG 7.52017-03-18
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
- CVE-2016-3017HIGHCVSS 7.5EG 7.52017-02-01
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.
- CVE-2019-14823HIGHCVSS 7.4EG 7.42019-10-14
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not p…
- CVE-2018-16857HIGHCVSS 7.4EG 7.42018-11-28
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary ris…
- CVE-2026-57915HIGHCVSS 7.3EG 7.32026-06-26
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
- CVE-2025-58308HIGHCVSS 3.3EG 7.32025-11-28
Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2026-29103HIGHCVSS 7.2EG 7.22026-03-19
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to ex…
- CVE-2025-32086HIGHCVSS 7.2EG 7.22025-08-12
Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via loca…
- CVE-2024-2617HIGHCVSS 7.2EG 7.22024-04-30
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerabil…
- CVE-2021-31375HIGHCVSS 7.2EG 7.22021-10-19
An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BG…
- CVE-2026-44473HIGHCVSS 7.1EG 7.12026-05-27
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the S…
- CVE-2017-15091HIGHCVSS 7.1EG 7.12018-01-23
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the…
- CVE-2026-14440MEDIUMCVSS 6.8EG 6.82026-07-02
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "lets…
- CVE-2021-26105MEDIUMCVSS 6.8EG 6.82025-03-24
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via speci…
- CVE-2026-11127MEDIUMCVSS 6.5EG 6.52026-06-04
Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted WebAPK. (Chromium security severity: Medium)
- CVE-2024-5500MEDIUMCVSS 6.5EG 6.52024-07-16
Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-22156MEDIUMCVSS 6.5EG 6.52022-01-19
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may comprom…
- CVE-2018-20934MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
- CVE-2024-23592MEDIUMCVSS 6.3EG 6.32024-04-05
An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.
- CVE-2016-8614MEDIUMCVSS 6.3EG 6.32018-07-31
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct ke…
- CVE-2026-11122MEDIUMCVSS 6.1EG 6.12026-06-04
Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-44475MEDIUMCVSS 6.1EG 6.12026-05-27
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella…
- CVE-2026-42081MEDIUMCVSS 6.1EG 6.12026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values, as mandated by …
- CVE-2025-31970MEDIUMCVSS 6.1EG 6.12026-05-06
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vec…
- CVE-2025-66601MEDIUMCVSS 6.1EG 6.12026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scripts could be executed. The affected …
- CVE-2025-31969MEDIUMCVSS 6.1EG 6.12025-10-12
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.
- CVE-2020-1761MEDIUMCVSS 6.1EG 6.12021-05-27
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw …
- CVE-2026-22618MEDIUMCVSS 5.9EG 5.92026-04-16
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed…
- CVE-2023-28113MEDIUMCVSS 5.9EG 5.92023-03-16
russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentialit…
- CVE-2021-42017MEDIUMCVSS 5.9EG 5.92022-03-08
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M969, RUGGEDCOM M969F, RUGGEDCOM RMC30, RUGGEDCOM RMC838…
- CVE-2016-8635MEDIUMCVSS 5.3EG 5.92018-08-01
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of th…
- CVE-2026-28914MEDIUMCVSS 5.5EG 5.52026-05-11
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
- CVE-2025-66323MEDIUMCVSS 5.5EG 5.52025-12-08
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-3838MEDIUMCVSS 5.5EG 5.52024-04-17
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)
- CVE-2017-2612MEDIUMCVSS 5.4EG 5.42018-05-15
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
- CVE-2026-65058MEDIUMCVSS 5.3EG 5.32026-07-21
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to t…
- CVE-2026-25315MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects hCaptcha for WP: from n/a through <= 4.21.1.
- CVE-2025-66607MEDIUMCVSS 5.3EG 5.32026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker. The affected products and versions…
- CVE-2025-25255MEDIUMCVSS 5.3EG 5.32025-10-14
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7…
- CVE-2021-34791MEDIUMCVSS 5.3EG 5.32021-10-27
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticate…
- CVE-2021-34790MEDIUMCVSS 5.3EG 5.32021-10-27
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticate…
- CVE-2017-15706MEDIUMCVSS 5.3EG 5.32018-01-31
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify w…
- CVE-2017-15105MEDIUMCVSS 5.3EG 5.32018-01-23
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick …
- CVE-2017-12303MEDIUMCVSS 5.3EG 5.32017-11-16
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule…
Map vulnerabilities like CWE-358 to your infrastructure
EchelonGraph correlates every CVE — across CWE-358 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →