Fallos del tipo CWE-353

43 resultados

Ausência de verificação de integridade

Ocorre quando um software transmite ou armazena dados sem mecanismo de proteção contra modificações não autorizadas. Um atacante pode alterar os dados em trânsito ou em repouso, e o sistema não detecta a mudança, causando corrupção de informações críticas ou execução de operações maliciosas.

Ejemplo

Um servidor envia um arquivo de configuração para um cliente sem checksum ou assinatura digital. Um atacante intercepta a comunicação e modifica o arquivo para alterar credenciais de acesso ou desabilitar verificações de segurança. Como não há validação de integridade, o cliente aceita o arquivo corrompido como legítimo.

Cómo mitigar

Implemente mecanismos de verificação de integridade: use hashes criptográficos (SHA-256+), assinaturas digitais (HMAC ou RSA), ou protocolos autenticados (TLS com certificados válidos). Valide a integridade antes de usar qualquer dado recebido ou restaurado de armazenamento.

CVE-2021-28545HIGHAcrobat Reader DC Missing Support for Integrity CheckEPSS 2.3%CVE-2021-28546MEDIUMAcrobat Reader DC Missing Support for Integrity CheckEPSS 1.4%CVE-2019-10943A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.EPSS 1.0%CVE-2020-10124NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host EPSS 0.7%CVE-2020-7878An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue isEPSS 0.7%CVE-2020-7808HIGHRAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerabilityEPSS 0.7%CVE-2021-26608HIGHhandysoft groupware arbitrary file download and execution vulnerabilityEPSS 0.6%CVE-2019-19160MEDIUMReportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxpEPSS 0.6%CVE-2023-29290MEDIUMAdobe Commerce Guest Cart Shipping Address Overwrite IDOR EPSS 0.6%CVE-2019-11480HIGHUbuntu kernel snap build process could use unauthenticated sourcesEPSS 0.5%CVE-2020-10266HIGHRVD#1487: No integrity checks on UR+ platform artifacts when installed in the robotEPSS 0.5%CVE-2020-7810HIGHHandySoft ActiveX File Download and Execution VulnerabilityEPSS 0.4%CVE-2021-26610HIGHgodomall5 remote code execution vulnerabilityEPSS 0.4%CVE-2019-12804HIGHHunesion i-oneNet Missing Support for Integrity Check vulnerabilityEPSS 0.4%CVE-2022-24404MEDIUMCiphertext Malleability in TETRAEPSS 0.3%CVE-2023-28865MEDIUMDiebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory conteEPSS 0.3%CVE-2025-48811MEDIUMWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-48803MEDIUMWindows Virtualization-Based Security (VBS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-10010MEDIUMIntegrity Validation Bypass in CryptoPro Secure Disk for BitLockerEPSS 0.3%CVE-2024-46917HIGHDiebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validaEPSS 0.2%