Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certific
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerabi
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zo
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated att
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able t
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulner
A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in t
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from th
A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an
A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could all
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of response
com.proxyman.NSProxy.HelperTool in Privileged Helper Tool in Proxyman for macOS 1.11.0 and earlier allows an attacker to
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to wr
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additional
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a
Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvS
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bind
Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacke
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user session
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A maliciou
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficien
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS re
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.8
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to exec
In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, whi
Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of att
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via a
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Deleg
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over H
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying th
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started