Falhas do tipo CWE-924

24 resultados

Falta de Integridade de Mensagem em Transmissão

É quando um sistema envia dados pela rede sem verificar se a mensagem chegou íntegra, permitindo que um atacante intercepete, altere ou replique dados sem detecção. O risco é grave porque dados críticos (autenticação, comandos, transações) podem ser corrompidos silenciosamente.

Exemplo

Um dispositivo IoT comunica com seu servidor enviando comandos de controle por TCP sem assinatura ou hash de validação. Um atacante na rede local modifica o pacote para 'desligar sistema' e o servidor executa sem questionar, porque nunca verificou se o conteúdo foi alterado.

Como mitigar

Use HMAC ou assinatura digital para cada mensagem antes de enviar, validando no destino. Combine sempre com TLS/DTLS para criptografia do canal e considere numeração de sequência para detectar repeticão de mensagens antigas.

CVE-2021-21390MEDIUMMITM modification of request bodies in MinIOEPSS 0.9%CVE-2022-3166HIGHMicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition AttackEPSS 0.7%CVE-2021-34793HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service VulnerabilityEPSS 0.6%CVE-2021-3716A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use tEPSS 0.6%CVE-2024-43450HIGHWindows DNS Spoofing VulnerabilityEPSS 0.6%CVE-2023-3347MEDIUMSamba: smb2 packet signing is not enforced when "server signing = required" is setEPSS 0.4%CVE-2024-44730CRITICALIncorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat EPSS 0.4%CVE-2021-41034The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence EPSS 0.4%CVE-2025-0592HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.3%CVE-2020-10635MEDIUMICSA-20-098-05 KUKA.Sim Pro Improper Enforcement of Message Integrity During Transmission in a Communication ChannelEPSS 0.3%CVE-2023-6408HIGH CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a dEPSS 0.3%CVE-2023-2885HIGHChannel Accessible by Non-Endpoint in CBOT's ChatbotEPSS 0.3%CVE-2024-8933HIGHCWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrEPSS 0.3%CVE-2025-29628CRITICALA Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home EPSS 0.3%CVE-2023-22372MEDIUMBIG-IP Edge Client for Windows and Mac OS vulnerabilityEPSS 0.2%CVE-2024-39229MEDIUMAn issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X3EPSS 0.2%CVE-2024-12399MEDIUMCWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partEPSS 0.2%CVE-2026-12576HIGHDVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerabilityEPSS 0.2%CVE-2023-30565LOW CQI Data Sniffing EPSS 0.1%CVE-2026-54891MEDIUMPlaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslEPSS 0.1%