Vulnerabilities > Download of Code Without Integrity Check

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-45321 Download of Code Without Integrity Check vulnerability in App::Cpanminus Project App::Cpanminus
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
network
low complexity
app CWE-494
critical
9.8
2024-02-06 CVE-2023-47353 Download of Code Without Integrity Check vulnerability in Imoulife Imou GO 1.0.11
An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.
network
low complexity
imoulife CWE-494
8.8
2023-12-14 CVE-2023-46143 Download of Code Without Integrity Check vulnerability in Phoenixcontact products
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.
network
low complexity
phoenixcontact CWE-494
7.5
2023-12-14 CVE-2023-46144 Download of Code Without Integrity Check vulnerability in Phoenixcontact products
A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices.
network
low complexity
phoenixcontact CWE-494
6.5
2023-12-14 CVE-2023-5592 Download of Code Without Integrity Check vulnerability in Phoenixcontact Multiprog and Proconos Eclr
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.
network
low complexity
phoenixcontact CWE-494
7.5
2023-12-14 CVE-2023-5630 Download of Code Without Integrity Check vulnerability in Schneider-Electric products
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.
network
low complexity
schneider-electric CWE-494
4.9
2023-12-05 CVE-2023-43608 Download of Code Without Integrity Check vulnerability in Buildroot 2023.08.1
A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847.
network
high complexity
buildroot CWE-494
8.1
2023-12-05 CVE-2023-45838 Download of Code Without Integrity Check vulnerability in Buildroot 2023.08.1
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847.
network
high complexity
buildroot CWE-494
8.1
2023-12-05 CVE-2023-45839 Download of Code Without Integrity Check vulnerability in Buildroot 2023.08.1
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847.
network
high complexity
buildroot CWE-494
8.1
2023-12-05 CVE-2023-45840 Download of Code Without Integrity Check vulnerability in Buildroot 2023.08.1
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847.
network
high complexity
buildroot CWE-494
8.1