Fallos del tipo CWE-924

24 resultados

Falta de integridade de mensagens em canal de comunicação

Ocorre quando dados trafegam por um canal de comunicação sem mecanismo que garanta que a mensagem não foi alterada em trânsito. Um atacante pode interceptar, modificar e reenviar dados sem que o receptor perceba — causando corrupção de informações críticas, injeção de comandos maliciosos ou desvio do fluxo esperado.

Ejemplo

Um sistema IoT envia comandos de controle via HTTP sem HMAC ou assinatura digital. Um atacante na rede intercepta o pacote 'temperatura=25', altera para 'temperatura=80' e reenvia. O dispositivo executa a instrução modificada sem validar autenticidade, causando malfunction.

Cómo mitigar

Implemente verificação de integridade obrigatória: use HMAC-SHA256, assinatura digital (RSA/ECDSA) ou TLS 1.2+ com cipher suites autenticadas. Para APIs, adicione tokens JWT assinados ou use mTLS. Sempre valide a assinatura antes de processar a mensagem no lado receptor.

CVE-2021-21390MEDIUMMITM modification of request bodies in MinIOEPSS 0.9%CVE-2022-3166HIGHMicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition AttackEPSS 0.7%CVE-2021-34793HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service VulnerabilityEPSS 0.6%CVE-2021-3716A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use tEPSS 0.6%CVE-2024-43450HIGHWindows DNS Spoofing VulnerabilityEPSS 0.6%CVE-2023-3347MEDIUMSamba: smb2 packet signing is not enforced when "server signing = required" is setEPSS 0.4%CVE-2024-44730CRITICALIncorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat EPSS 0.4%CVE-2021-41034The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence EPSS 0.4%CVE-2025-0592HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.3%CVE-2020-10635MEDIUMICSA-20-098-05 KUKA.Sim Pro Improper Enforcement of Message Integrity During Transmission in a Communication ChannelEPSS 0.3%CVE-2023-6408HIGH CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a dEPSS 0.3%CVE-2023-2885HIGHChannel Accessible by Non-Endpoint in CBOT's ChatbotEPSS 0.3%CVE-2024-8933HIGHCWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrEPSS 0.3%CVE-2025-29628CRITICALA Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home EPSS 0.3%CVE-2023-22372MEDIUMBIG-IP Edge Client for Windows and Mac OS vulnerabilityEPSS 0.2%CVE-2024-39229MEDIUMAn issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X3EPSS 0.2%CVE-2024-12399MEDIUMCWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partEPSS 0.2%CVE-2026-12576HIGHDVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerabilityEPSS 0.2%CVE-2023-30565LOW CQI Data Sniffing EPSS 0.1%CVE-2026-54891MEDIUMPlaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslEPSS 0.1%