Fallos del tipo CWE-353

43 resultados

Ausência de verificação de integridade

Ocorre quando um software transmite ou armazena dados sem mecanismo de proteção contra modificações não autorizadas. Um atacante pode alterar os dados em trânsito ou em repouso, e o sistema não detecta a mudança, causando corrupção de informações críticas ou execução de operações maliciosas.

Ejemplo

Um servidor envia um arquivo de configuração para um cliente sem checksum ou assinatura digital. Um atacante intercepta a comunicação e modifica o arquivo para alterar credenciais de acesso ou desabilitar verificações de segurança. Como não há validação de integridade, o cliente aceita o arquivo corrompido como legítimo.

Cómo mitigar

Implemente mecanismos de verificação de integridade: use hashes criptográficos (SHA-256+), assinaturas digitais (HMAC ou RSA), ou protocolos autenticados (TLS com certificados válidos). Valide a integridade antes de usar qualquer dado recebido ou restaurado de armazenamento.

CVE-2026-33261MEDIUMNull pointer accces in aggressive NSEC(3) cacheEPSS 0.2%CVE-2020-7807MEDIUMDLL Hijacking Vulnerabilities During Installation of LG Electronics SoftwareEPSS 0.2%CVE-2024-27817HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey EPSS 0.2%CVE-2025-15364HIGHDownload Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePasswordEPSS 0.2%CVE-2021-38396MEDIUMMissing Support Integrity Check for Boston Scientific Zoom LatitudeEPSS 0.2%CVE-2020-9062Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2023-32475HIGHDell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypEPSS 0.2%CVE-2026-18536HIGHData::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTPEPSS 0.2%CVE-2026-48995MEDIUMpnpm: Tarball hash of GitHub git dependencies is not stored in lockfileEPSS 0.2%CVE-2026-3856MEDIUMIBM Db2 Recovery Expert Missing Integrity CheckEPSS 0.2%CVE-2026-21437LOWeopkg vulnerable to package file list integrity bypassEPSS 0.2%CVE-2022-2793MEDIUMEmerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no aEPSS 0.1%CVE-2026-7574HIGHAnthropic Claude Desktop Cowork VM Image Contents Not Validated Before UseEPSS 0.1%CVE-2026-42428HIGHOpenClaw < 2026.4.8 - Missing Integrity Verification in Package DownloadsEPSS 0.1%CVE-2026-17583HIGHThermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity CheckEPSS 0.1%CVE-2025-32890MEDIUMAn issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without anEPSS 0.1%CVE-2025-65203HIGHKeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directivEPSS 0.1%CVE-2025-48500HIGHBIG-IP APM VPN web client for macOS vulnerabilityEPSS 0.1%CVE-2026-45787MEDIUMelecterm's encrypt method not safe enoughEPSS 0.1%CVE-2026-12705MEDIUMIntegrity mechanism of KNX-device FW-files can be bypassed in ABB Update ToolEPSS 0.1%