Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2021-08-30 CVE-2021-37421 Insufficient Verification of Data Authenticity vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
network
low complexity
zohocorp CWE-345
critical
9.8
2021-08-25 CVE-2021-1586 Insufficient Verification of Data Authenticity vulnerability in Cisco Nx-Os 15.0(2E)/15.1(1H)
A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-345
8.6
2021-08-12 CVE-2021-38597 Insufficient Verification of Data Authenticity vulnerability in Wolfssl
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
network
high complexity
wolfssl CWE-345
5.9
2021-08-05 CVE-2021-21739 Insufficient Verification of Data Authenticity vulnerability in ZTE Zxctn 6120H Firmware 5.10.00B24
A ZTE's product of the transport network access layer has a security vulnerability.
low complexity
zte CWE-345
4.6
2021-08-03 CVE-2021-22419 Insufficient Verification of Data Authenticity vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability.
local
low complexity
huawei CWE-345
5.5
2021-07-12 CVE-2021-21588 Insufficient Verification of Data Authenticity vulnerability in Dell Powerflex Presentation Server 3.5
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI.
network
low complexity
dell CWE-345
4.3
2021-07-09 CVE-2021-36367 Insufficient Verification of Data Authenticity vulnerability in Putty
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.
network
low complexity
putty CWE-345
8.1
2021-06-24 CVE-2021-23998 Insufficient Verification of Data Authenticity vulnerability in Mozilla Thunderbird
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page.
network
low complexity
mozilla CWE-345
6.5
2021-06-24 CVE-2021-29963 Insufficient Verification of Data Authenticity vulnerability in Mozilla Firefox
Address bar search suggestions in private browsing mode were re-using session data from normal mode.
network
low complexity
mozilla CWE-345
4.3
2021-06-15 CVE-2021-33887 Insufficient Verification of Data Authenticity vulnerability in Onepeloton Ttr01 Firmware Ptv55G
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.
low complexity
onepeloton CWE-345
6.8