CWE-354
170 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
CVEs (170)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Quagga RedhatSuse4Opensuse Package ManagerQuagga+1 moreNov 21, 2024 Jul 24, 2018 N/A· v4 8.2 HIGH· v3 4.3 MEDIUM· v2 Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same...Show more |
1Tlslite Ng Project 1Tlslite Ng Nov 21, 2024 Apr 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper Validation of Integrity Check Value vulnerability in TLS implementation, tlslite/utils/constanttime...Show more |
2Bouncycastle Redhat3Bc Java SatelliteSatellite CapsuleJun 17, 2026 Apr 16, 2018 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bi...Show more |
1Phoenixcontact 23Mguard Centerport Firmware Mguard Core Tx Vpn FirmwareMguard Delta Tx/tx Firmware+20 moreJun 17, 2026 Jan 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the u...Show more |
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the...Show more |
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attack...Show more |
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack. |
2Comcast Motorola2Mx011anm Firmware Xfinity Xr11 20 FirmwareMay 13, 2026 Jul 31, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access....Show more |
1Infotecs 2Vipnet Client Vipnet CoordinatorMay 13, 2026 Jun 15, 2017 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permission...Show more |
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow the...Show more |