CWE-924— Improper Enforcement of Message Integrity During Transmission in a Communication Channel
33 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-924page 1 of 1
- CVE-2015-0897MEDIUMCVSS 5.9EG 5.92023-10-31
LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a scr…
- CVE-2015-2968MEDIUMCVSS 5.9EG 5.92023-10-31
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM…
- CVE-2018-14526MEDIUMCVSS 6.5EG 6.52018-08-08
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and cli…
- CVE-2018-7295HIGHCVSS 8.1EG 8.12018-05-23
ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During Transmission in a Communication Channel, allowing a man-in-the-middle attacker to steal user creden…
- CVE-2019-14808MEDIUMCVSS 6.8EG 6.82019-10-09
An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., exposure of his birthday) or logs into hi…
- CVE-2019-20844MEDIUMCVSS 6.5EG 6.52020-06-19
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
- CVE-2019-25719HIGHCVSS 8.6EG 8.62026-06-02
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tampe…
- CVE-2020-10635MEDIUMCVSS 4.3EG 4.32022-02-24
Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a model, the server transmits the model in plaintext.
- CVE-2020-11639HIGHCVSS 7.8EG 7.82024-07-23
An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. The process could crash or cause communication issues on the affect…
- CVE-2020-5869CRITICALCVSS 9.1EG 9.12020-04-24
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.
- CVE-2021-21390MEDIUMCVSS 6.5EG 6.52021-03-19
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-17T02-33-02Z, there is a vulnerability which enables MITM modification o…
- CVE-2021-34793HIGHCVSS 8.6EG 8.62021-10-27
A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address table…
- CVE-2021-3716LOWCVSS 3.1EG 3.12022-03-02
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client se…
- CVE-2021-41034HIGHCVSS 8.1EG 8.12021-09-29
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original…
- CVE-2022-3166HIGHCVSS 7.5EG 7.52022-12-16
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with n…
- CVE-2023-22372MEDIUMCVSS 5.9EG 5.92023-05-03
In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-26979LOWCVSS 3.1EG 3.12023-08-03
Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communic…
- CVE-2023-2885HIGHCVSS 8.1EG 9.92023-05-25
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM). This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
- CVE-2023-30565LOWCVSS 3.5EG 3.52023-07-13
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
- CVE-2023-3347MEDIUMCVSS 5.9EG 5.92023-07-20
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is manda…
- CVE-2023-43297MEDIUMCVSS 5.4EG 5.42023-10-02
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- CVE-2023-49933HIGHCVSS 7.5EG 7.52023-12-14
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During Transmission in a Communication Channel. This allows attackers to modify RPC traffic in a way that bypasses m…
- CVE-2023-6408HIGHCVSS 8.1EG 8.12024-02-14
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the…
- CVE-2024-12399HIGHCVSS 7.1EG 7.12025-01-17
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs m…
- CVE-2024-3596CRITICALCVSS 9.0EG 9.02024-07-09
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against…
- CVE-2024-39229MEDIUMCVSS 5.3EG 5.32024-08-06
An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/M…
- CVE-2024-43450HIGHCVSS 7.5EG 7.52024-11-12
Windows DNS Spoofing Vulnerability
- CVE-2024-44730CRITICALCVSS 9.1EG 9.12024-10-11
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
- CVE-2024-52288MEDIUMCVSS 5.1EG 5.12024-11-11
libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In affected versions an unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` may be introduced in…
- CVE-2024-8933HIGHCVSS 7.5EG 7.52024-11-13
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integri…
- CVE-2025-0592HIGHCVSS 8.8EG 8.82025-02-14
The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.
- CVE-2025-29628CRITICALCVSS 9.4EG 8.12025-07-25
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vu…
- CVE-2026-39827MEDIUMCVSS 6.5EG 6.52026-05-22
An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly remo…
Map vulnerabilities like CWE-924 to your infrastructure
EchelonGraph correlates every CVE — across CWE-924 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →