CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
662 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 7 of 14
- CVE-2023-0350MEDIUMCVSS 6.5EG 6.52023-03-13
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to upload a file to the device by changing the extension of a malicious file to an accepted file type.
- CVE-2023-20236MEDIUMCVSS 6.7EG 6.72023-09-13
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification.…
- CVE-2023-2030LOWCVSS 3.5EG 3.52024-01-12
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
- CVE-2023-20570LOWCVSS 3.3EG 3.32024-02-13
Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.
- CVE-2023-21441HIGHCVSS 7.4EG 7.42023-02-09
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
- CVE-2023-22315HIGHCVSS 6.7EG 7.82023-01-30
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary…
- CVE-2023-22955HIGHCVSS 7.8EG 7.82023-08-11
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store th…
- CVE-2023-2314MEDIUMCVSS 6.5EG 6.52023-07-29
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2023-23940MEDIUMCVSS 6.4EG 6.42023-02-03
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signatu…
- CVE-2023-23941HIGHCVSS 7.5EG 7.52023-02-03
SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be id…
- CVE-2023-25178CRITICALCVSS 9.8EG 9.82023-07-13
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-26141HIGHCVSS 7.5EG 7.52023-09-14
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will…
- CVE-2023-26467MEDIUMCVSS 5.4EG 5.42023-04-10
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
- CVE-2023-26481CRITICALCVSS 9.1EG 9.12023-03-04
authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is onl…
- CVE-2023-27360HIGHCVSS 8.8EG 8.82024-05-03
NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to explo…
- CVE-2023-27748CRITICALCVSS 9.8EG 9.82023-04-13
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.
- CVE-2023-27977HIGHCVSS 6.5EG 7.52023-03-21
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific…
- CVE-2023-27979HIGHCVSS 6.5EG 7.52023-03-21
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends spec…
- CVE-2023-27982HIGHCVSS 8.8EG 8.82023-03-21
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to th…
- CVE-2023-28386HIGHCVSS 8.6EG 8.62023-05-22
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system f…
- CVE-2023-28457HIGHCVSS 7.5EG 7.52024-09-18
An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.
- CVE-2023-2866HIGHCVSS 7.3EG 7.32023-06-07
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
- CVE-2023-28863CRITICALCVSS 9.1EG 9.12023-04-18
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
- CVE-2023-28865MEDIUMCVSS 6.6EG 6.62024-08-08
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization…
- CVE-2023-2897LOWCVSS 3.7EG 3.72023-06-09
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose o…
- CVE-2023-2987CRITICALCVSS 9.8EG 9.82023-05-31
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible fo…
- CVE-2023-3028HIGHCVSS 8.6EG 8.62023-06-01
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected to…
- CVE-2023-30559MEDIUMCVSS 5.2EG 5.22023-07-13
The firmware update package for the wireless card is not properly signed and can be modified.
- CVE-2023-30562MEDIUMCVSS 6.7EG 6.72023-07-13
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
- CVE-2023-30759HIGHCVSS 7.8EG 7.82023-06-19
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driv…
- CVE-2023-31502HIGHCVSS 7.2EG 7.22023-05-11
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php.
- CVE-2023-32329MEDIUMCVSS 6.2EG 6.22024-02-03
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to…
- CVE-2023-32993MEDIUMCVSS 4.8EG 4.82023-05-16
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to interce…
- CVE-2023-3325HIGHCVSS 8.1EG 8.12023-06-20
The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible…
- CVE-2023-35719MEDIUMCVSS 6.8EG 6.82023-09-06
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of M…
- CVE-2023-35764MEDIUMCVSS 5.3EG 5.32024-04-03
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
- CVE-2023-35906MEDIUMCVSS 5.3EG 5.32023-09-05
IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.
- CVE-2023-36134CRITICALCVSS 9.8EG 9.82023-08-04
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- CVE-2023-36139CRITICALCVSS 9.8EG 9.82023-08-04
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- CVE-2023-36541HIGHCVSS 8.0EG 8.02023-08-08
Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.
- CVE-2023-3663HIGHCVSS 8.8EG 8.82023-08-03
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification se…
- CVE-2023-36858HIGHCVSS 7.1EG 7.12023-08-02
An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support …
- CVE-2023-37264LOWCVSS 3.7EG 3.72023-07-07
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.35.0, pipelines do not validate child UIDs, which means that a user that has access to create TaskRuns can create their own Ta…
- CVE-2023-3749HIGHCVSS 7.1EG 7.12023-08-03
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
- CVE-2023-37920HIGHCVSS 7.5EG 7.52023-07-25
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's ro…
- CVE-2023-38552HIGHCVSS 7.5EG 7.52023-10-18
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the int…
- CVE-2023-38831CRITICALCVSS 7.8EG 9.0⚠ KEV2023-08-23
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also…
- CVE-2023-3920MEDIUMCVSS 4.3EG 4.32023-09-29
An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a for…
- CVE-2023-39347HIGHCVSS 7.6EG 7.62023-09-27
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to update pod labels can cause Cilium to apply incorrect network policies. This issue arises due to the fact that on po…
- CVE-2023-41045MEDIUMCVSS 5.3EG 5.32023-08-31
Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket for outgoing DNS queries and while that socket is bound to a random port number it is never…
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →