Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2022-12-28 CVE-2022-3347 Insufficient Verification of Data Authenticity vulnerability in Go-Resolver Project Go-Resolver
DNSSEC validation is not performed correctly.
network
low complexity
go-resolver-project CWE-345
7.5
2022-12-26 CVE-2022-30260 Insufficient Verification of Data Authenticity vulnerability in Emerson products
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature).
local
low complexity
emerson CWE-345
7.8
2022-12-16 CVE-2022-26579 Insufficient Verification of Data Authenticity vulnerability in Paxtechnology Paydroid 7.1.1Virgov04.3.26T120210419
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages.
local
low complexity
paxtechnology CWE-345
6.0
2022-12-12 CVE-2022-37928 Insufficient Verification of Data Authenticity vulnerability in HPE products
Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
network
low complexity
hpe CWE-345
6.5
2022-12-08 CVE-2022-39909 Insufficient Verification of Data Authenticity vulnerability in Samsung Gear Iconx PC Manager 2.1.220405.51
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.
local
low complexity
samsung CWE-345
5.5
2022-12-07 CVE-2022-23491 Insufficient Verification of Data Authenticity vulnerability in multiple products
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts.
network
low complexity
certifi netapp CWE-345
7.5
2022-11-28 CVE-2022-31877 Insufficient Verification of Data Authenticity vulnerability in MSI Center 1.0.41.0
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
network
low complexity
msi CWE-345
8.8
2022-11-25 CVE-2022-41156 Insufficient Verification of Data Authenticity vulnerability in Etm-S Ondiskplayeragent 1.3.8.12
Remote code execution vulnerability due to insufficient verification of URLs, etc.
local
low complexity
etm-s CWE-345
7.8
2022-11-09 CVE-2022-0031 Insufficient Verification of Data Authenticity vulnerability in Paloaltonetworks Cortex Xsoar 6.5.0/6.6.0/6.8.0
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
local
low complexity
paloaltonetworks CWE-345
6.7
2022-11-08 CVE-2022-27513 Insufficient Verification of Data Authenticity vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Remote desktop takeover via phishing
network
low complexity
citrix CWE-345
critical
9.6