CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
660 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 4 of 14
- CVE-2020-24045HIGHCVSS 7.2EG 7.22020-09-17
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by present…
- CVE-2020-24395MEDIUMCVSS 6.8EG 6.82021-05-20
The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can le…
- CVE-2020-24672CRITICALCVSS 9.8EG 9.82021-09-08
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
- CVE-2020-25019HIGHCVSS 7.5EG 7.52020-08-29
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
- CVE-2020-26547CRITICALCVSS 9.8EG 9.82021-02-01
Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full co…
- CVE-2020-26893HIGHCVSS 7.8EG 7.82020-10-16
An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (running with an injected malicious dylib) to communicate with ClamXAV 3's helper tool and perform privileged operations. Th…
- CVE-2020-27670HIGHCVSS 7.8EG 7.82020-10-22
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated.
- CVE-2020-28900CRITICALCVSS 9.8EG 9.82021-05-24
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_t…
- CVE-2020-3174MEDIUMCVSS 4.7EG 4.72020-02-26
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addr…
- CVE-2020-3220MEDIUMCVSS 6.8EG 6.82020-06-03
A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimat…
- CVE-2020-5964HIGHCVSS 7.8EG 7.82020-06-25
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or info…
- CVE-2020-6081HIGHCVSS 8.8EG 8.82020-05-07
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a mal…
- CVE-2020-6090HIGHCVSS 7.2EG 7.22020-06-11
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An at…
- CVE-2020-6443HIGHCVSS 8.8EG 8.82020-04-13
Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.
- CVE-2020-7487CRITICALCVSS 9.8EG 9.82020-04-22
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
- CVE-2020-7878CRITICALCVSS 9.8EG 9.82021-12-28
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.
- CVE-2020-7982HIGHCVSS 8.1EG 8.12020-03-16
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, …
- CVE-2020-8660MEDIUMCVSS 5.3EG 5.32020-03-04
CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have bee…
- CVE-2020-9109MEDIUMCVSS 4.6EG 4.62020-10-12
There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the vic…
- CVE-2020-9141CRITICALCVSS 9.1EG 9.12021-01-13
There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information disclosure and malfunctions due to insufficient verification of data authenticity.
- CVE-2020-9230MEDIUMCVSS 6.5EG 6.52020-10-12
WS5800-10 version 10.0.3.25 has a denial of service vulnerability. Due to improper verification of specific message, an attacker may exploit this vulnerability to cause specific function to become abnormal.
- CVE-2020-9885MEDIUMCVSS 5.5EG 5.52020-10-16
An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an…
- CVE-2021-1403HIGHCVSS 7.4EG 7.42021-03-24
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. …
- CVE-2021-1586HIGHCVSS 8.6EG 8.62021-08-25
A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the …
- CVE-2021-20267HIGHCVSS 7.1EG 7.12021-05-28
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems o…
- CVE-2021-20271HIGHCVSS 7.0EG 7.02021-03-26
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM databa…
- CVE-2021-21231HIGHCVSS 8.8EG 8.82021-04-30
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-21320LOWCVSS 2.6EG 2.62021-03-02
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a…
- CVE-2021-21588MEDIUMCVSS 6.5EG 6.52021-07-12
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted acti…
- CVE-2021-21739MEDIUMCVSS 4.6EG 4.62021-08-05
A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unau…
- CVE-2021-22339MEDIUMCVSS 6.5EG 6.52021-05-20
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some servic…
- CVE-2021-22419MEDIUMCVSS 5.5EG 5.52021-08-03
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
- CVE-2021-22460MEDIUMCVSS 5.5EG 5.52021-10-28
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.
- CVE-2021-22947MEDIUMCVSS 5.9EG 5.92021-09-29
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to T…
- CVE-2021-23998MEDIUMCVSS 6.5EG 6.52021-06-24
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
- CVE-2021-24825MEDIUMCVSS 4.3EG 4.32022-03-07
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such…
- CVE-2021-26103MEDIUMCVSS 6.3EG 6.32021-12-08
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may all…
- CVE-2021-26315HIGHCVSS 7.8EG 7.82021-11-16
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when e…
- CVE-2021-26368MEDIUMCVSS 4.4EG 4.42022-05-12
Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.
- CVE-2021-26396MEDIUMCVSS 4.4EG 4.42023-01-11
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
- CVE-2021-26403MEDIUMCVSS 6.5EG 6.52023-01-11
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.
- CVE-2021-26608CRITICALCVSS 8.8EG 9.82021-09-09
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.
- CVE-2021-26610HIGHCVSS 7.2EG 7.22021-10-27
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
- CVE-2021-26625HIGHCVSS 8.8EG 8.82022-04-19
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version informat…
- CVE-2021-27759MEDIUMCVSS 2.3EG 6.52022-05-06
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary …
- CVE-2021-28678MEDIUMCVSS 5.5EG 5.52021-06-02
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times o…
- CVE-2021-29239HIGHCVSS 7.8EG 7.82021-05-03
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.
- CVE-2021-29462HIGHCVSS 7.6EG 7.62021-04-20
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Hos…
- CVE-2021-29655CRITICALCVSS 9.8EG 9.82022-02-18
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
- CVE-2021-29963MEDIUMCVSS 4.3EG 4.32021-06-24
Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →