Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2020-03-04 CVE-2020-8660 Insufficient Verification of Data Authenticity vulnerability in Envoyproxy Envoy
CNCF Envoy through 1.13.0 TLS inspector bypass.
network
low complexity
envoyproxy CWE-345
5.3
2020-02-26 CVE-2020-3174 Insufficient Verification of Data Authenticity vulnerability in Cisco Nx-Os 8.1(1)/8.4(1)/9.3(1)
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries.
low complexity
cisco CWE-345
4.7
2020-02-24 CVE-2019-17228 Insufficient Verification of Data Authenticity vulnerability in Stylemixthemes Motors - CAR Dealer, Classifieds & Listing
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
network
low complexity
stylemixthemes CWE-345
6.5
2020-02-24 CVE-2019-12510 Insufficient Verification of Data Authenticity vulnerability in Netgear Nighthawk X10-R9000 Firmware 1.0.4.24
In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request.
network
low complexity
netgear CWE-345
critical
9.1
2020-02-19 CVE-2016-1000004 Insufficient Verification of Data Authenticity vulnerability in Facebook Hhvm
Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom.
network
low complexity
facebook CWE-345
critical
9.8
2020-02-18 CVE-2019-5613 Insufficient Verification of Data Authenticity vulnerability in Freebsd 12.0
In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint.
network
low complexity
freebsd CWE-345
critical
9.8
2020-02-04 CVE-2019-15613 Insufficient Verification of Data Authenticity vulnerability in multiple products
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
network
low complexity
nextcloud opensuse CWE-345
8.0
2019-12-29 CVE-2019-20057 Insufficient Verification of Data Authenticity vulnerability in Proxyman
com.proxyman.NSProxy.HelperTool in Privileged Helper Tool in Proxyman for macOS 1.11.0 and earlier allows an attacker to change the System Proxy and redirect all traffic to an attacker-controlled computer, enabling MITM attacks.
network
high complexity
proxyman CWE-345
3.7
2019-12-17 CVE-2019-18829 Insufficient Verification of Data Authenticity vulnerability in Barco Clickshare Button R9861500D01 Firmware
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check.
local
low complexity
barco CWE-345
7.8
2019-12-17 CVE-2019-18824 Insufficient Verification of Data Authenticity vulnerability in Barco Clickshare Button R9861500D01 Firmware
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check.
low complexity
barco CWE-345
6.6