CWE-345
645 CVEs • Abstraction: Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attacker could exploit the vulnerability to cause remote code execution by causing an arbitrary user to do...Show more |
immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified tra...Show more |
immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances...Show more |
1Etictelecom 1Remote Access Server Firmware Jun 17, 2026 Nov 10, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to...Show more |
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with...Show more |
1Citrix 2Application Delivery Controller Firmware GatewayJun 17, 2026 Nov 8, 2022 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Remote desktop takeover via phishing
|
1Fortinet 3Antivirus Engine FortimailFortiosJun 17, 2026 Nov 2, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV en...Show more |
A firmware update vulnerability exists in the sysupgrade functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network packet can lead to arbitrary firmware update. An attacker can send a sequence of requ...Show more |
1Siemens 2Logo!8 Bm Fs 05 Firmware Logo! 8 Bm FirmwareJun 17, 2026 Oct 11, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firm...Show more |
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with n...Show more |
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scop...Show more |
1Patlite 3Nbm D88n Firmware Nhl 3fb1 FirmwareNhl 3fv1n FirmwareJun 17, 2026 Aug 29, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own c...Show more |
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the conditio...Show more |
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this f...Show more |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection f...Show more |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic. |
The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnera...Show more |
1Emerson 2Controlwave Micro Firmware Controlwave Pac FirmwareJun 17, 2026 Aug 17, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containin...Show more |
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. |
1Emerson 5Dl8000 Firmware Fb3000 Rtu FirmwareRoc800l Firmware+2 moreJun 17, 2026 Aug 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 20...Show more |