Weaknesses of type CWE-353

49 results

Ausência de verificação de integridade

A aplicação transmite ou armazena dados sem mecanismos que garantam que eles não foram alterados. Um atacante consegue modificar os dados em trânsito ou em repouso sem ser detectado, comprometendo a confiabilidade das informações processadas.

Example

Um serviço envia um arquivo de configuração pela rede sem hash ou assinatura digital. Um atacante intercepta o arquivo e muda parâmetros críticos; o servidor aplica a configuração modificada sem saber que foi adulterada.

How to mitigate

Implemente verificação de integridade usando HMAC, assinatura digital (RSA, ECDSA) ou hash criptográfico (SHA-256). Valide sempre a integridade antes de processar dados sensíveis, especialmente em APIs, arquivos de configuração e dados em repouso.

CVE-2024-46917HIGHDiebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validaEPSS 0.2%CVE-2026-33261MEDIUMNull pointer accces in aggressive NSEC(3) cacheEPSS 0.2%CVE-2026-76853HIGHNetcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgiEPSS 0.2%CVE-2026-17583HIGHThermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity CheckEPSS 0.2%CVE-2025-15364HIGHDownload Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePasswordEPSS 0.2%CVE-2020-7807MEDIUMDLL Hijacking Vulnerabilities During Installation of LG Electronics SoftwareEPSS 0.2%CVE-2024-27817HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey EPSS 0.2%CVE-2021-38396MEDIUMMissing Support Integrity Check for Boston Scientific Zoom LatitudeEPSS 0.2%CVE-2020-9062Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2026-48995MEDIUMpnpm: Tarball hash of GitHub git dependencies is not stored in lockfileEPSS 0.2%CVE-2026-21437LOWeopkg vulnerable to package file list integrity bypassEPSS 0.2%CVE-2023-32475HIGHDell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%CVE-2026-12705MEDIUMIntegrity mechanism of KNX-device FW-files can be bypassed in ABB Update ToolEPSS 0.2%CVE-2026-3856MEDIUMIBM Db2 Recovery Expert Missing Integrity CheckEPSS 0.2%CVE-2022-2793MEDIUMEmerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no aEPSS 0.1%CVE-2026-42428HIGHOpenClaw < 2026.4.8 - Missing Integrity Verification in Package DownloadsEPSS 0.1%CVE-2025-65203HIGHKeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directivEPSS 0.1%CVE-2026-84533MEDIUMA cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS EPSS 0.1%CVE-2026-49450HIGHJoplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherNameEPSS 0.1%