CWE-354
170 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
CVEs (170)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signatu...Show more |
1Huawei 2P30 Firmware P30 Pro FirmwareJun 17, 2026 Jun 18, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain so...Show more |
SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer. |
1Huawei 4Osca 550 Firmware Osca 550a FirmwareOsca 550ax Firmware+1 moreJun 17, 2026 Apr 10, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently validate the integrity of certain file in certain loading processes, successful exploit could allow the at...Show more |
An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity che...Show more |
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos5433, Exynos7420, or Exynos7870 chipsets) software. An attacker can bypass a ko (aka Kernel Module) signature by modifying the count of kern...Show more |
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system im...Show more |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Mar 23, 2020 N/A· v4 6.4 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute cod...Show more |
1Huawei 6Hege 560 Firmware Hege 570 FirmwareOsca 550 Firmware+3 moreJun 17, 2026 Mar 20, 2020 N/A· v4 3.9 LOW· v3 3.6 LOW· v2 There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifi...Show more |
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make...Show more |
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks th...Show more |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough |
1Oneidentity 1Cloud Access Manager Jun 17, 2026 Nov 4, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Oct 10, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'. |
Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in specific versions of Junos OS, affecting specific EX Series platforms, the V...Show more |
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to upd...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Aug 14, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signatu...Show more |
5Fedoraproject LibreswanRedhat+2 more5Enterprise Linux FedoraLibreswan+2 moreJun 17, 2026 Jun 12, 2019 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a r...Show more |
Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privilege escalation by replacing the original EnableLoopback.exe. |
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool wi...Show more |