CWE-642 · 18 записей
External Control of Critical State Data
CVE этого класса
18 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2020-27872Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routnetgear · ac2100 firmware · CWE-642 | Высокая8,8 | — | 0,9 % | 4 февр. 2021 г. |
34Наблюдать | CVE-2018-15382Эксплойта нет | Cisco HyperFlex Software Static Signing Key Vulnerabilitycisco · hyperflex hx data platform · CWE-642 | Высокая8,6 | — | 1,3 % | 5 окт. 2018 г. |
32Наблюдать | CVE-2024-8754Эксплойта нет | External Control of Critical State Data in GitLabgitlab · gitlab · CWE-642 | Высокая8,1 | — | 0,4 % | 12 сент. 2024 г. |
31Наблюдать | CVE-2019-9496Эксплойта нет | An invalid authentication sequence could result in the hostapd process terminating due to missing state validation stepsw1.fi · hostapd · CWE-642 | Высокая7,5 | — | 4,7 % | 17 апр. 2019 г. |
28Наблюдать | CVE-2025-49090Эксплойта нет | The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.matrix · matrix specification · CWE-642 | Высокая7,1 | — | 0,5 % | 2 окт. 2025 г. |
27Наблюдать | CVE-2020-26186Эксплойта нет | Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.dell · inspiron 5675 firmware · CWE-642 | Средняя6,8 | — | 0,4 % | 8 янв. 2021 г. |
27Наблюдать | CVE-2024-22387Эксплойта нет | External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticategallagher · controller 6000 and controller 7000 · CWE-642 | Средняя6,8 | — | 0,3 % | 10 июл. 2024 г. |
27Наблюдать | CVE-2022-22154Эксплойта нет | Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoSjuniper · junos · CWE-642 | Средняя6,8 | — | 0,2 % | 18 янв. 2022 г. |
24Наблюдать | CVE-2017-0928Эксплойта нет | html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variabletheguardian · html-janitor · CWE-642 | Средняя6,1 | — | 1,0 % | 4 июн. 2018 г. |
22Наблюдать | CVE-2020-1976Эксплойта нет | GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.paloaltonetworks · globalprotect · CWE-642 | Средняя5,5 | — | 0,3 % | 12 февр. 2020 г. |
21Наблюдать | CVE-2022-32859Эксплойта нет | A logic issue was addressed with improved state management.apple · iphone os · CWE-642 | Средняя5,3 | — | 0,6 % | 1 нояб. 2022 г. |
21Наблюдать | CVE-2025-54566Эксплойта нет | hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.qemu · qemu · CWE-642 | Средняя5,4 | — | 0,2 % | 24 июл. 2025 г. |
18Наблюдать | CVE-2025-26787Эксплойта нет | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.keyfactor · signserver · CWE-642 | Средняя4,7 | — | 0,1 % | 22 дек. 2025 г. |
17Наблюдать | CVE-2024-58265Эксплойта нет | The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message deliverymcginty · snow · CWE-642 | Средняя4,3 | — | 0,4 % | 27 июл. 2025 г. |
17Наблюдать | CVE-2026-65355Эксплойта нет | An information disclosure issue was addressed with improved state management.apple · ipados · CWE-642 | Средняя4,3 | — | 0,3 % | 14 сент. 2026 г. |
17Наблюдать | CVE-2026-84518Эксплойта нет | This issue was addressed through improved state management.apple · safari · CWE-642 | Средняя4,3 | — | 0,3 % | 14 сент. 2026 г. |
17Наблюдать | CVE-2026-65352Эксплойта нет | An information disclosure issue was addressed with improved state management.apple · ipados · CWE-642 | Средняя4,3 | — | 0,3 % | 14 сент. 2026 г. |
12Наблюдать | GHSA-97f8-h76h-f297Эксплойта нет | Duplicate Advisory: Unauthenticated Nonce Increment in snowcrates.io · snow · CWE-642 | Низкая3,1 | — | — | 28 июл. 2025 г. |
- CVE-2020-2787235Наблюдать
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %netgear · ac2100 firmware4 февр. 2021 г.
- CVE-2018-1538234Наблюдать
Cisco HyperFlex Software Static Signing Key Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %cisco · hyperflex hx data platform5 окт. 2018 г.
- CVE-2024-875432Наблюдать
External Control of Critical State Data in GitLab
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %gitlab · gitlab12 сент. 2024 г.
- CVE-2019-949631Наблюдать
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %w1.fi · hostapd17 апр. 2019 г.
- CVE-2025-4909028Наблюдать
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %matrix · matrix specification2 окт. 2025 г.
- CVE-2020-2618627Наблюдать
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dell · inspiron 5675 firmware8 янв. 2021 г.
- CVE-2024-2238727Наблюдать
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticate
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gallagher · controller 6000 and controller 700010 июл. 2024 г.
- CVE-2022-2215427Наблюдать
Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
СредняяCVSS 6,8Эксплойта нетEPSS 0 %juniper · junos18 янв. 2022 г.
- CVE-2017-092824Наблюдать
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable
СредняяCVSS 6,1Эксплойта нетEPSS 1 %theguardian · html-janitor4 июн. 2018 г.
- CVE-2020-197622Наблюдать
GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %paloaltonetworks · globalprotect12 февр. 2020 г.
- CVE-2022-3285921Наблюдать
A logic issue was addressed with improved state management.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %apple · iphone os1 нояб. 2022 г.
- CVE-2025-5456621Наблюдать
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %qemu · qemu24 июл. 2025 г.
- CVE-2025-2678718Наблюдать
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.
СредняяCVSS 4,7Эксплойта нетEPSS 0 %keyfactor · signserver22 дек. 2025 г.
- CVE-2024-5826517Наблюдать
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery
СредняяCVSS 4,3Эксплойта нетEPSS 0 %mcginty · snow27 июл. 2025 г.
- CVE-2026-6535517Наблюдать
An information disclosure issue was addressed with improved state management.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %apple · ipados14 сент. 2026 г.
- CVE-2026-8451817Наблюдать
This issue was addressed through improved state management.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %apple · safari14 сент. 2026 г.
- CVE-2026-6535217Наблюдать
An information disclosure issue was addressed with improved state management.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %apple · ipados14 сент. 2026 г.
- GHSA-97f8-h76h-f29712Наблюдать
Duplicate Advisory: Unauthenticated Nonce Increment in snow
НизкаяCVSS 3,1Эксплойта нетcrates.io · snow28 июл. 2025 г.