← Back
CWE-345

645 CVEs • Abstraction: Class

Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

JSON object

Loading...

CVEs (645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hex
1Hex Core
Jun 17, 2026
Feb 4, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack...Show more
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0.Show less
1Hex
1Hex
Jun 17, 2026
Feb 4, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appea...Show more
Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.19.Show less
1Logmx
1Logmx
Jun 17, 2026
Feb 4, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update...Show more
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update process relies on cleartext HTTP. The attacker could replace the LogMXUpdater.class file.Show less
1Powerdns
1Recursor
Jun 17, 2026
Jan 29, 2019
N/A· v4
9.8 CRITICAL· v3
6.4 MEDIUM· v2
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing...Show more
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.Show less
1Vmware
1Spring Framework
Nov 21, 2024
Dec 19, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be us...Show more
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.Show less
1Schneider Electric
1Somachine Basic
Jun 17, 2026
Nov 2, 2018
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected t...Show more
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.Show less
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
Oct 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
1Medtronic
2Mycarelink 24950 Patient Monitor Firmware
Mycarelink 24952 Patient Monitor Firmware
May 19, 2026
Aug 10, 2018
N/A· v4
4.4 MEDIUM· v3
3.8 LOW· v2
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac...Show more
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Aug 1, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
3Quagga
RedhatSuse
4Opensuse
Package ManagerQuagga+1 more
Nov 21, 2024
Jul 24, 2018
N/A· v4
8.2 HIGH· v3
4.3 MEDIUM· v2
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same...Show more
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge. In a case where the sequence numbers are the same, the LSA with the larger checksum is considered more recent, and will not be flushed from the Link State Database (LSDB). Since the RFC does not explicitly state that the values of links carried by a LSA must be the same when prematurely aging a self-originating LSA with MaxSequenceNumber, it is possible in vulnerable OSPF implementations for an attacker to craft a LSA with MaxSequenceNumber and invalid links that will result in a larger checksum and thus a 'newer' LSA that will not be flushed from the LSDB. Propagation of the crafted LSA can result in the erasure or alteration of the routing tables of routers within the routing domain, creating a denial of service condition or the re-routing of traffic on the network. CVE-2017-3224 has been reserved for Quagga and downstream implementations (SUSE, openSUSE, and Red Hat packages).Show less
1Sap
3Netweaver
Ui InfraUser Interface Technology
Nov 21, 2024
Jul 10, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implemen...Show more
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.Show less
1Gigabyte
2Gb Bsi7h 6500 Firmware
Gb Bxi7 5775 Firmware
Nov 21, 2024
Jul 9, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmw...Show more
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.Show less
1Ecos
1Secure Boot Stick Firmware
Nov 21, 2024
Jun 17, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code.
1Ibm
1Security Identity Manager
Nov 21, 2024
Jun 8, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392.
1Totemo
1Totemomail Encryption Gateway
Jun 17, 2026
May 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.
1Huawei
1Appgallery
Jun 17, 2026
Apr 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the white...Show more
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.Show less
1Secutech Project
3Ris 11 Firmware
Ris 22 FirmwareRis 33 Firmware
Nov 21, 2024
Apr 13, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.
2Redhat
Theforeman
3Hammer Cli
SatelliteSatellite Capsule
Nov 21, 2024
Mar 12, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections...Show more
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.Show less
1Ibm
1Datapower Gateway
Nov 21, 2024
Jan 31, 2018
N/A· v4
4.0 MEDIUM· v3
4.3 MEDIUM· v2
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
1Siemens
1Logo! Soft Comfort
May 13, 2026
Dec 26, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software p...Show more
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.Show less