CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
660 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 5 of 14
- CVE-2021-30005HIGHCVSS 7.8EG 7.82021-05-11
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
- CVE-2021-31228HIGHCVSS 7.5EG 7.52021-08-19
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's r…
- CVE-2021-31783HIGHCVSS 7.5EG 7.52021-04-26
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
- CVE-2021-32665HIGHCVSS 8.8EG 8.82021-06-03
wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unverified. This occurs when: - Self user is added to a new conve…
- CVE-2021-3349LOWCVSS 3.3EG 3.32021-02-01
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significan…
- CVE-2021-33712HIGHCVSS 8.8EG 8.82021-06-08
A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2). The configuration of the SAML module does not properly check various restrictions and validations imposed by an identity provider. This could allow a remote…
- CVE-2021-33840HIGHCVSS 7.5EG 7.52021-06-04
The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.
- CVE-2021-33885CRITICALCVSS 10.0EG 10.02021-08-25
An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This resul…
- CVE-2021-33887MEDIUMCVSS 6.8EG 6.82021-06-15
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.
- CVE-2021-34572MEDIUMCVSS 6.5EG 6.52021-09-16
Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.
- CVE-2021-36367HIGHCVSS 8.1EG 8.12021-07-09
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that…
- CVE-2021-36751CRITICALCVSS 4.2EG 9.12022-01-02
ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect th…
- CVE-2021-37188HIGHCVSS 8.8EG 8.82021-12-10
An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.
- CVE-2021-37421CRITICALCVSS 9.8EG 9.82021-08-30
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
- CVE-2021-38396MEDIUMCVSS 6.5EG 6.82021-10-04
The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted U…
- CVE-2021-38597MEDIUMCVSS 5.9EG 5.92021-08-12
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
- CVE-2021-39158HIGHCVSS 8.8EG 8.82021-08-23
NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to i…
- CVE-2021-39689MEDIUMCVSS 6.7EG 6.72022-03-16
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not …
- CVE-2021-4031HIGHCVSS 7.5EG 7.52022-03-18
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed withou…
- CVE-2021-40491MEDIUMCVSS 6.5EG 6.52021-09-03
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
- CVE-2021-41087MEDIUMCVSS 5.6EG 5.62021-09-21
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to …
- CVE-2021-41106MEDIUMCVSS 4.4EG 4.42021-09-28
JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-based algorithms (HS256, HS384, and HS512) combined with `Lcobucci\JWT\Signer\Key\LocalFileReference` as key are …
- CVE-2021-41203HIGHCVSS 7.8EG 7.82021-11-05
TensorFlow is an open source platform for machine learning. In affected versions an attacker can trigger undefined behavior, integer overflows, segfaults and `CHECK`-fail crashes if they can change saved checkpoints from outside of TensorF…
- CVE-2021-4122MEDIUMCVSS 4.3EG 4.32022-08-24
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user…
- CVE-2021-4226CRITICALCVSS 9.8EG 9.82022-12-15
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
- CVE-2021-43616CRITICALCVSS 9.0EG 9.82021-11-13
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for …
- CVE-2021-44850MEDIUMCVSS 6.8EG 6.82022-02-10
On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the …
- CVE-2021-45419HIGHCVSS 8.8EG 8.82021-12-22
Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.
- CVE-2021-46559HIGHCVSS 7.5EG 7.52022-01-26
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.
- CVE-2022-0031MEDIUMCVSS 6.7EG 6.72022-11-09
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
- CVE-2022-0715CRITICALCVSS 9.1EG 9.12022-03-09
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Seri…
- CVE-2022-20396MEDIUMCVSS 5.5EG 5.52022-09-13
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execut…
- CVE-2022-20774HIGHCVSS 6.8EG 8.12022-04-06
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a…
- CVE-2022-20795HIGHCVSS 5.8EG 7.52022-04-21
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high C…
- CVE-2022-20829CRITICALCVSS 9.1EG 9.12022-06-24
A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrati…
- CVE-2022-2255HIGHCVSS 7.5EG 7.52022-08-25
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is m…
- CVE-2022-22567MEDIUMCVSS 4.7EG 4.72022-02-09
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmwa…
- CVE-2022-22757MEDIUMCVSS 6.5EG 6.52022-12-22
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, whi…
- CVE-2022-22994CRITICALCVSS 8.8EG 9.82022-01-28
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the de…
- CVE-2022-23491MEDIUMCVSS 6.8EG 6.82022-12-07
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These …
- CVE-2022-23556HIGHCVSS 7.0EG 7.02022-12-22
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configur…
- CVE-2022-24889LOWCVSS 2.4EG 2.42022-04-27
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server…
- CVE-2022-25262CRITICALCVSS 9.8EG 9.82022-02-25
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- CVE-2022-26122HIGHCVSS 4.7EG 8.62022-11-02
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulati…
- CVE-2022-26516HIGHCVSS 8.4EG 8.42022-04-20
Authorized users may install a maliciously modified package file when updating the device via the web user interface. The user may inadvertently use a package file obtained from an unauthorized source or a file that was compromised between…
- CVE-2022-26579MEDIUMCVSS 6.0EG 6.02022-12-16
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages. The attacker must have shell access to the device and gain root privileges in order to exploit this vulnerabil…
- CVE-2022-26871CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-29
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
- CVE-2022-27513CRITICALCVSS 8.3EG 9.62022-11-08
Remote desktop takeover via phishing
- CVE-2022-2789MEDIUMCVSS 4.7EG 5.52022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.
- CVE-2022-2793HIGHCVSS 5.9EG 7.82022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protoco…
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →