CWE-358— Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.— MITRE CWE catalog
138 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-358page 3 of 3
- CVE-2017-6032MEDIUMCVSS 5.3EG 5.32017-06-30
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.
- CVE-2014-4843MEDIUMCVSS 5.3EG 5.32017-06-08
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via v…
- CVE-2024-55599MEDIUMCVSS 4.9EG 5.32025-07-08
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all ve…
- CVE-2024-3844MEDIUMCVSS 4.3EG 5.32024-04-17
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
- CVE-2026-54431MEDIUMCVSS 5.1EG 5.12026-07-02
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_…
- CVE-2025-43262MEDIUMCVSS 5.1EG 5.12025-09-15
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. USB Restricted Mode may not be applied to accessories connected during boot.
- CVE-2020-7251MEDIUMCVSS 5.0EG 5.02020-02-14
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from o…
- CVE-2025-13333MEDIUMCVSS 4.9EG 4.92026-02-17
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
- CVE-2020-1728MEDIUMCVSS 4.8EG 4.82020-04-06
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, ye…
- CVE-2020-9295MEDIUMCVSS 4.7EG 4.72025-03-17
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-s…
- CVE-2025-31983MEDIUMCVSS 4.6EG 4.62026-05-06
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure…
- CVE-2017-8152MEDIUMCVSS 4.6EG 4.62017-11-22
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page without authorization …
- CVE-2025-21267MEDIUMCVSS 4.4EG 4.42025-02-06
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2021-26328MEDIUMCVSS 4.4EG 4.42023-01-11
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
- CVE-2026-5894MEDIUMCVSS 4.3EG 4.32026-04-08
Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2025-62002MEDIUMCVSS 4.3EG 4.32025-12-18
BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multip…
- CVE-2025-10457MEDIUMCVSS 4.3EG 4.32025-09-19
The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.
- CVE-2024-33510MEDIUMCVSS 4.3EG 4.32024-11-12
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 a…
- CVE-2022-27220MEDIUMCVSS 4.3EG 4.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the …
- CVE-2022-27219MEDIUMCVSS 4.3EG 4.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the s…
- CVE-2020-10743MEDIUMCVSS 4.3EG 4.32021-06-02
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary…
- CVE-2017-2604MEDIUMCVSS 4.3EG 4.32018-05-15
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).
- CVE-2017-2611MEDIUMCVSS 4.3EG 4.32018-05-08
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read ac…
- CVE-2024-41907MEDIUMCVSS 4.2EG 4.22024-08-13
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers…
- CVE-2021-3448MEDIUMCVSS 4.0EG 4.02021-04-08
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port use…
- CVE-2026-46582LOWCVSS 3.7EG 3.72026-07-22
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation trea…
- CVE-2026-44474LOWCVSS 3.7EG 3.72026-05-27
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could send a NAS Security Mode Command while …
- CVE-2026-42082LOWCVSS 3.7EG 3.72026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1. The AMF does not check for ongoing N2 handove…
- CVE-2025-8204LOWCVSS 3.7EG 3.72025-07-26
A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerability is an unknown functionality of the component HSTS Handler. The manipulation leads to security check for standard. The…
- CVE-2025-49011LOWCVSS 3.7EG 3.72025-06-06
SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request i…
- CVE-2024-36511LOWCVSS 3.7EG 3.72024-09-10
An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all…
- CVE-2020-25686LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstr…
- CVE-2020-25685LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due …
- CVE-2020-25684LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does no…
- CVE-2026-35679LOWCVSS 3.5EG 3.52026-04-05
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
- CVE-2023-2585LOWCVSS 3.5EG 3.52023-12-21
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent…
- CVE-2020-8352LOWCVSS 2.4EG 2.42020-11-11
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
- CVE-2024-12056LOWCVSS 2.3EG 2.32024-12-04
The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. E…
Map vulnerabilities like CWE-358 to your infrastructure
EchelonGraph correlates every CVE — across CWE-358 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →