Vulnerabilities > Improper Validation of Integrity Check Value

DATE CVE VULNERABILITY TITLE RISK
2023-02-02 CVE-2023-23120 Improper Validation of Integrity Check Value vulnerability in Trendnet Tv-Ip651Wi Firmware
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks.
network
high complexity
trendnet CWE-354
5.9
2022-12-19 CVE-2022-46402 Improper Validation of Integrity Check Value vulnerability in Microchip products
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
low complexity
microchip CWE-354
6.5
2022-10-11 CVE-2022-36360 Improper Validation of Integrity Check Value vulnerability in Siemens Logo!8 BM Fs-05 Firmware and Logo! 8 BM Firmware
A vulnerability has been identified in LOGO! 8 BM (incl.
network
low complexity
siemens CWE-354
7.5
2022-09-20 CVE-2022-38955 Improper Validation of Integrity Check Value vulnerability in Netgear Wpn824Ext Firmware 1.1.11.1.9
An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender.
network
high complexity
netgear CWE-354
7.5
2022-09-20 CVE-2022-38956 Improper Validation of Integrity Check Value vulnerability in Netgear Wpn824Ext Firmware 1.1.11.1.9
An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender.
network
high complexity
netgear CWE-354
5.3
2022-08-15 CVE-2022-35961 Improper Validation of Integrity Check Value vulnerability in Openzeppelin Contracts and Contracts Upgradeable
OpenZeppelin Contracts is a library for secure smart contract development.
network
low complexity
openzeppelin CWE-354
6.5
2022-07-12 CVE-2022-33711 Improper Validation of Integrity Check Value vulnerability in Samsung Android USB Driver
Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction.
local
low complexity
samsung CWE-354
2.1
2022-06-14 CVE-2021-37182 Improper Validation of Integrity Check Value vulnerability in Siemens products
A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 1x230V (All versions < V6.5), SCALANCE XR524-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 24V (All versions < V6.5), SCALANCE XR524-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 2x230V (All versions < V6.5), SCALANCE XR524-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 1x230V (All versions < V6.5), SCALANCE XR526-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 24V (All versions < V6.5), SCALANCE XR526-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 2x230V (All versions < V6.5), SCALANCE XR526-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR528-6M (All versions < V6.5), SCALANCE XR528-6M (2HR2) (All versions < V6.5), SCALANCE XR528-6M (2HR2, L3 int.) (All versions < V6.5), SCALANCE XR528-6M (L3 int.) (All versions < V6.5), SCALANCE XR552-12M (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2, L3 int.) (All versions < V6.5).
network
siemens CWE-354
4.3
2022-06-06 CVE-2022-21757 Improper Validation of Integrity Check Value vulnerability in Google Android 11.0/12.0
In WIFI Firmware, there is a possible system crash due to a missing count check.
network
low complexity
google CWE-354
7.8
2022-05-11 CVE-2022-29898 Improper Validation of Integrity Check Value vulnerability in Phoenixcontact products
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.
network
low complexity
phoenixcontact CWE-354
critical
9.0