CWE-924 · 35 records
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CVEs in this class
35 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-29628Proof of concept | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home gardyn · home kit firmware · CWE-924 | Critical9.4 | — | 0.3% | Jul 25, 2025 |
36Monitor | CVE-2020-5869No exploit | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidenf5 · big-iq centralized management · CWE-924 | Critical9.1 | — | 0.5% | Apr 24, 2020 |
36Monitor | CVE-2024-44730No exploit | Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat CWE-924 | Critical9.1 | — | 0.4% | Oct 11, 2024 |
35Monitor | CVE-2025-0592No exploit | SICK Lector8xx and InspectorP8xx vulnerable for code executionsick ag · sick lector8xx · CWE-924 | High8.8 | — | 0.4% | Feb 14, 2025 |
35Monitor | CVE-2019-25719No exploit | Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handlingdräger · infinity acute care system · CWE-924 | High8.8 | — | 0.1% | Jun 2, 2026 |
34Monitor | CVE-2021-34793No exploit | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerabilitycisco · adaptive security appliance · CWE-924 | High8.6 | — | 0.6% | Oct 27, 2021 |
32Monitor | CVE-2018-7295No exploit | ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During square-enix · final fantasy xiv · CWE-924 | High8.1 | — | 0.4% | May 23, 2018 |
32Monitor | CVE-2021-41034No exploit | The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint.eclipse · che · CWE-924 | High8.1 | — | 0.4% | Sep 29, 2021 |
32Monitor | CVE-2023-6408No exploit | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a dschneider-electric · modicon m340 bmxp341000 firmware · CWE-924 | High8.1 | — | 0.3% | Feb 14, 2024 |
32Monitor | CVE-2023-2885No exploit | Channel Accessible by Non-Endpoint in CBOT's Chatbotcbot · cbot core · CWE-924 | High8.1 | — | 0.3% | May 25, 2023 |
31Monitor | CVE-2020-11639No exploit | Insufficient access control on Inter process communication,abb · advabuild · CWE-924 | High7.8 | — | 0.1% | Jul 23, 2024 |
30Monitor | CVE-2022-3166No exploit | MicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition Attackrockwellautomation · micrologix 1100 firmware · CWE-924 | High7.5 | — | 0.7% | Dec 16, 2022 |
30Monitor | CVE-2024-43450No exploit | Windows DNS Spoofing Vulnerabilitymicrosoft · windows server 2008 · CWE-924 | High7.5 | — | 0.6% | Nov 12, 2024 |
30Monitor | CVE-2023-49933No exploit | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x.schedmd · slurm · CWE-924 | High7.5 | — | 0.4% | Dec 14, 2023 |
30Monitor | CVE-2024-8933No exploit | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrschneider electric · modicon m340 cpu (part numbers bmxp34*) · CWE-924 | High7.5 | — | 0.3% | Nov 13, 2024 |
30Monitor | CVE-2026-12576No exploit | DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerabilitydeltaww · dvp80es3 · CWE-924 | High7.5 | — | 0.2% | Jul 1, 2026 |
28Monitor | CVE-2026-13584No exploit | Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocolmitsubishi electric corporation · melsec mx controller mx-r model mxr300-16 · CWE-924 | High7.1 | — | 0.2% | Jul 30, 2026 |
27Monitor | GHSA-vhmj-5q9r-mm9gNo exploit | BlastRADIUS also affects eduMFAPyPI · edumfa · CWE-924 | Medium6.8 | — | — | Jul 17, 2024 |
26Monitor | CVE-2018-14526No exploit | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6.canonical · ubuntu linux · CWE-924 | Medium6.5 | — | 1.5% | Aug 8, 2018 |
26Monitor | CVE-2019-20844No exploit | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7.mattermost · mattermost server · CWE-924 | Medium6.5 | — | 0.4% | Jun 19, 2020 |
26Monitor | CVE-2026-39827No exploit | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshgolang · crypto · CWE-924 | Medium6.5 | — | 0.3% | May 22, 2026 |
25Monitor | CVE-2026-54891No exploit | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslerlang · erlang\/otp · CWE-924 | Medium6.3 | — | 0.2% | Jul 2, 2026 |
24Monitor | CVE-2024-12399No exploit | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partschneider electric · pro-face gp-pro ex · CWE-924 | Medium6.1 | — | 0.2% | Jan 17, 2025 |
23Monitor | CVE-2021-21390No exploit | MITM modification of request bodies in MinIOminio · minio · CWE-924 | Medium5.9 | — | 0.9% | Mar 19, 2021 |
23Monitor | CVE-2023-22372No exploit | BIG-IP Edge Client for Windows and Mac OS vulnerabilityf5 · big-ip access policy manager · CWE-924 | Medium5.9 | — | 0.2% | May 3, 2023 |
- CVE-2025-2962837Monitor
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home
CriticalCVSS 9.4Proof of conceptEPSS 0%gardyn · home kit firmwareJul 25, 2025
- CVE-2020-586936Monitor
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confiden
CriticalCVSS 9.1No exploitEPSS 0%f5 · big-iq centralized managementApr 24, 2020
- CVE-2024-4473036Monitor
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat
CriticalCVSS 9.1No exploitEPSS 0%Oct 11, 2024
- CVE-2025-059235Monitor
SICK Lector8xx and InspectorP8xx vulnerable for code execution
HighCVSS 8.8No exploitEPSS 0%sick ag · sick lector8xxFeb 14, 2025
- CVE-2019-2571935Monitor
Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
HighCVSS 8.8No exploitEPSS 0%dräger · infinity acute care systemJun 2, 2026
- CVE-2021-3479334Monitor
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerability
HighCVSS 8.6No exploitEPSS 1%cisco · adaptive security applianceOct 27, 2021
- CVE-2018-729532Monitor
ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During
HighCVSS 8.1No exploitEPSS 0%square-enix · final fantasy xivMay 23, 2018
- CVE-2021-4103432Monitor
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint.
HighCVSS 8.1No exploitEPSS 0%eclipse · cheSep 29, 2021
- CVE-2023-640832Monitor
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a d
HighCVSS 8.1No exploitEPSS 0%schneider-electric · modicon m340 bmxp341000 firmwareFeb 14, 2024
- CVE-2023-288532Monitor
Channel Accessible by Non-Endpoint in CBOT's Chatbot
HighCVSS 8.1No exploitEPSS 0%cbot · cbot coreMay 25, 2023
- CVE-2020-1163931Monitor
Insufficient access control on Inter process communication,
HighCVSS 7.8No exploitEPSS 0%abb · advabuildJul 23, 2024
- CVE-2022-316630Monitor
MicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition Attack
HighCVSS 7.5No exploitEPSS 1%rockwellautomation · micrologix 1100 firmwareDec 16, 2022
- CVE-2024-4345030Monitor
Windows DNS Spoofing Vulnerability
HighCVSS 7.5No exploitEPSS 1%microsoft · windows server 2008Nov 12, 2024
- CVE-2023-4993330Monitor
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x.
HighCVSS 7.5No exploitEPSS 0%schedmd · slurmDec 14, 2023
- CVE-2024-893330Monitor
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retr
HighCVSS 7.5No exploitEPSS 0%schneider electric · modicon m340 cpu (part numbers bmxp34*)Nov 13, 2024
- CVE-2026-1257630Monitor
DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
HighCVSS 7.5No exploitEPSS 0%deltaww · dvp80es3Jul 1, 2026
- CVE-2026-1358428Monitor
Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
HighCVSS 7.1No exploitEPSS 0%mitsubishi electric corporation · melsec mx controller mx-r model mxr300-16Jul 30, 2026
- GHSA-vhmj-5q9r-mm9g27Monitor
BlastRADIUS also affects eduMFA
MediumCVSS 6.8No exploitPyPI · edumfaJul 17, 2024
- CVE-2018-1452626Monitor
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6.
MediumCVSS 6.5No exploitEPSS 1%canonical · ubuntu linuxAug 8, 2018
- CVE-2019-2084426Monitor
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7.
MediumCVSS 6.5No exploitEPSS 0%mattermost · mattermost serverJun 19, 2020
- CVE-2026-3982726Monitor
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
MediumCVSS 6.5No exploitEPSS 0%golang · cryptoMay 22, 2026
- CVE-2026-5489125Monitor
Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
MediumCVSS 6.3No exploitEPSS 0%erlang · erlang\/otpJul 2, 2026
- CVE-2024-1239924Monitor
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause part
MediumCVSS 6.1No exploitEPSS 0%schneider electric · pro-face gp-pro exJan 17, 2025
- CVE-2021-2139023Monitor
MITM modification of request bodies in MinIO
MediumCVSS 5.9No exploitEPSS 1%minio · minioMar 19, 2021
- CVE-2023-2237223Monitor
BIG-IP Edge Client for Windows and Mac OS vulnerability
MediumCVSS 5.9No exploitEPSS 0%f5 · big-ip access policy managerMay 3, 2023