Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2023-03-21 CVE-2023-27977 Insufficient Verification of Data Authenticity vulnerability in Schneider-Electric Custom Reports, Igss Dashboard and Igss Data Server
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port.
network
low complexity
schneider-electric CWE-345
5.3
2023-03-21 CVE-2023-27982 Insufficient Verification of Data Authenticity vulnerability in Schneider-Electric Custom Reports, Igss Dashboard and Igss Data Server
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim eventually opens a malicious dashboard file.
network
low complexity
schneider-electric CWE-345
8.8
2023-03-13 CVE-2023-0350 Insufficient Verification of Data Authenticity vulnerability in Akuvox E11 Firmware
Akuvox E11 does not ensure that a file extension is associated with the file provided.
network
low complexity
akuvox CWE-345
6.5
2023-03-06 CVE-2017-20180 Insufficient Verification of Data Authenticity vulnerability in Zerocoin Libzerocoin
A vulnerability classified as critical has been found in Zerocoin libzerocoin.
network
low complexity
zerocoin CWE-345
7.5
2023-03-04 CVE-2023-26481 Insufficient Verification of Data Authenticity vulnerability in Goauthentik Authentik
authentik is an open-source Identity Provider.
network
low complexity
goauthentik CWE-345
6.5
2023-02-09 CVE-2023-21441 Insufficient Verification of Data Authenticity vulnerability in Samsung Android 10.0/11.0
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
local
low complexity
samsung CWE-345
5.5
2023-01-30 CVE-2023-22315 Insufficient Verification of Data Authenticity vulnerability in Snapav Wattbox Wb-300-Ip-3 Firmware Wb10.9A17
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device.
local
low complexity
snapav CWE-345
7.8
2023-01-12 CVE-2022-46370 Insufficient Verification of Data Authenticity vulnerability in Maxum Rumpus
Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification.
network
low complexity
maxum CWE-345
7.5
2023-01-11 CVE-2021-26396 Insufficient Verification of Data Authenticity vulnerability in AMD products
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
local
low complexity
amd CWE-345
4.4
2022-12-28 CVE-2022-3346 Insufficient Verification of Data Authenticity vulnerability in Go-Resolver Project Go-Resolver
DNSSEC validation is not performed correctly.
network
low complexity
go-resolver-project CWE-345
6.5