Skip to content
Noroxi

CWE-924 · 35 records

Improper Enforcement of Message Integrity During Transmission in a Communication Channel

CVEs in this class

35 records

  • A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home

    CriticalCVSS 9.4Proof of conceptEPSS 0%

    gardyn · home kit firmwareJul 25, 2025

  • CVE-2020-5869
    36Monitor

    In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confiden

    CriticalCVSS 9.1No exploitEPSS 0%

    f5 · big-iq centralized managementApr 24, 2020

  • Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat

    CriticalCVSS 9.1No exploitEPSS 0%

    Oct 11, 2024

  • CVE-2025-0592
    35Monitor

    SICK Lector8xx and InspectorP8xx vulnerable for code execution

    HighCVSS 8.8No exploitEPSS 0%

    sick ag · sick lector8xxFeb 14, 2025

  • Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling

    HighCVSS 8.8No exploitEPSS 0%

    dräger · infinity acute care systemJun 2, 2026

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerability

    HighCVSS 8.6No exploitEPSS 1%

    cisco · adaptive security applianceOct 27, 2021

  • CVE-2018-7295
    32Monitor

    ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During

    HighCVSS 8.1No exploitEPSS 0%

    square-enix · final fantasy xivMay 23, 2018

  • The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint.

    HighCVSS 8.1No exploitEPSS 0%

    eclipse · cheSep 29, 2021

  • CVE-2023-6408
    32Monitor

    CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a d

    HighCVSS 8.1No exploitEPSS 0%

    schneider-electric · modicon m340 bmxp341000 firmwareFeb 14, 2024

  • CVE-2023-2885
    32Monitor

    Channel Accessible by Non-Endpoint in CBOT's Chatbot

    HighCVSS 8.1No exploitEPSS 0%

    cbot · cbot coreMay 25, 2023

  • Insufficient access control on Inter process communication,

    HighCVSS 7.8No exploitEPSS 0%

    abb · advabuildJul 23, 2024

  • CVE-2022-3166
    30Monitor

    MicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition Attack

    HighCVSS 7.5No exploitEPSS 1%

    rockwellautomation · micrologix 1100 firmwareDec 16, 2022

  • Windows DNS Spoofing Vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    microsoft · windows server 2008Nov 12, 2024

  • An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x.

    HighCVSS 7.5No exploitEPSS 0%

    schedmd · slurmDec 14, 2023

  • CVE-2024-8933
    30Monitor

    CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retr

    HighCVSS 7.5No exploitEPSS 0%

    schneider electric · modicon m340 cpu (part numbers bmxp34*)Nov 13, 2024

  • DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    deltaww · dvp80es3Jul 1, 2026

  • Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol

    HighCVSS 7.1No exploitEPSS 0%

    mitsubishi electric corporation · melsec mx controller mx-r model mxr300-16Jul 30, 2026

  • BlastRADIUS also affects eduMFA

    MediumCVSS 6.8No exploit

    PyPI · edumfaJul 17, 2024

  • An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6.

    MediumCVSS 6.5No exploitEPSS 1%

    canonical · ubuntu linuxAug 8, 2018

  • An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7.

    MediumCVSS 6.5No exploitEPSS 0%

    mattermost · mattermost serverJun 19, 2020

  • Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

    MediumCVSS 6.5No exploitEPSS 0%

    golang · cryptoMay 22, 2026

  • Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl

    MediumCVSS 6.3No exploitEPSS 0%

    erlang · erlang\/otpJul 2, 2026

  • CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause part

    MediumCVSS 6.1No exploitEPSS 0%

    schneider electric · pro-face gp-pro exJan 17, 2025

  • MITM modification of request bodies in MinIO

    MediumCVSS 5.9No exploitEPSS 1%

    minio · minioMar 19, 2021

  • BIG-IP Edge Client for Windows and Mac OS vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    f5 · big-ip access policy managerMay 3, 2023

All vulnerability classes