Fallos del tipo CWE-353

49 resultados

Ausência de verificação de integridade

Ocorre quando um software transmite ou armazena dados sem mecanismo de proteção contra modificações não autorizadas. Um atacante pode alterar os dados em trânsito ou em repouso, e o sistema não detecta a mudança, causando corrupção de informações críticas ou execução de operações maliciosas.

Ejemplo

Um servidor envia um arquivo de configuração para um cliente sem checksum ou assinatura digital. Um atacante intercepta a comunicação e modifica o arquivo para alterar credenciais de acesso ou desabilitar verificações de segurança. Como não há validação de integridade, o cliente aceita o arquivo corrompido como legítimo.

Cómo mitigar

Implemente mecanismos de verificação de integridade: use hashes criptográficos (SHA-256+), assinaturas digitais (HMAC ou RSA), ou protocolos autenticados (TLS com certificados válidos). Valide a integridade antes de usar qualquer dado recebido ou restaurado de armazenamento.

CVE-2024-46917HIGHDiebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validaEPSS 0.2%CVE-2026-33261MEDIUMNull pointer accces in aggressive NSEC(3) cacheEPSS 0.2%CVE-2026-76853HIGHNetcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgiEPSS 0.2%CVE-2026-17583HIGHThermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity CheckEPSS 0.2%CVE-2025-15364HIGHDownload Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePasswordEPSS 0.2%CVE-2020-7807MEDIUMDLL Hijacking Vulnerabilities During Installation of LG Electronics SoftwareEPSS 0.2%CVE-2024-27817HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey EPSS 0.2%CVE-2021-38396MEDIUMMissing Support Integrity Check for Boston Scientific Zoom LatitudeEPSS 0.2%CVE-2020-9062Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2026-48995MEDIUMpnpm: Tarball hash of GitHub git dependencies is not stored in lockfileEPSS 0.2%CVE-2026-21437LOWeopkg vulnerable to package file list integrity bypassEPSS 0.2%CVE-2023-32475HIGHDell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%CVE-2026-12705MEDIUMIntegrity mechanism of KNX-device FW-files can be bypassed in ABB Update ToolEPSS 0.2%CVE-2026-3856MEDIUMIBM Db2 Recovery Expert Missing Integrity CheckEPSS 0.2%CVE-2022-2793MEDIUMEmerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no aEPSS 0.1%CVE-2026-42428HIGHOpenClaw < 2026.4.8 - Missing Integrity Verification in Package DownloadsEPSS 0.1%CVE-2025-65203HIGHKeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directivEPSS 0.1%CVE-2026-84533MEDIUMA cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS EPSS 0.1%CVE-2026-49450HIGHJoplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherNameEPSS 0.1%