Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2022-12-12 CVE-2022-37928 Insufficient Verification of Data Authenticity vulnerability in HPE products
Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
network
low complexity
hpe CWE-345
6.5
2022-12-08 CVE-2022-39909 Insufficient Verification of Data Authenticity vulnerability in Samsung Gear Iconx PC Manager 2.1.220405.51
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.
local
low complexity
samsung CWE-345
5.5
2022-12-07 CVE-2022-23491 Insufficient Verification of Data Authenticity vulnerability in Certifi Project Certifi
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts.
network
low complexity
certifi-project CWE-345
7.5
2022-11-28 CVE-2022-31877 Insufficient Verification of Data Authenticity vulnerability in MSI Center 1.0.41.0
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
network
low complexity
msi CWE-345
8.8
2022-11-25 CVE-2022-41156 Insufficient Verification of Data Authenticity vulnerability in Etm-S Ondiskplayeragent 1.3.8.12
Remote code execution vulnerability due to insufficient verification of URLs, etc.
local
low complexity
etm-s CWE-345
7.8
2022-11-23 CVE-2022-36111 Insufficient Verification of Data Authenticity vulnerability in Codenotary Immudb
immudb is a database with built-in cryptographic proof and verification.
network
high complexity
codenotary CWE-345
5.3
2022-11-22 CVE-2022-39199 Insufficient Verification of Data Authenticity vulnerability in Codenotary Immudb
immudb is a database with built-in cryptographic proof and verification.
network
high complexity
codenotary CWE-345
5.9
2022-11-10 CVE-2022-3703 Insufficient Verification of Data Authenticity vulnerability in Etictelecom Remote Access Server Firmware 4.5.0
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.
network
low complexity
etictelecom CWE-345
critical
10.0
2022-11-09 CVE-2022-0031 Insufficient Verification of Data Authenticity vulnerability in Paloaltonetworks Cortex Xsoar 6.5.0/6.6.0/6.8.0
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
local
low complexity
paloaltonetworks CWE-345
6.7
2022-11-08 CVE-2022-27513 Insufficient Verification of Data Authenticity vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Remote desktop takeover via phishing
network
low complexity
citrix CWE-345
critical
9.6