Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side C
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order
JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protoco
The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Leg
Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize th
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to t
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior
A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those ima
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platfor
Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation
The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contain
Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware fil
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a c
Authorized users may install a maliciously modified package file when updating the device via the web user interface. Th
Remote desktop takeover via phishing
Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Fla
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP
Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attack
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate check
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting maliciou
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection me
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associate
An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not v
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java appl
On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of pr
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploi
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, all
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load f
D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-25
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.22101
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the
NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, whi
On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the RO
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform F
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the c
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linu
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN
github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perf
TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version sel
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started