CWE-924 · 35 записей
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CVE этого класса
35 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2025-29628Proof of concept | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home gardyn · home kit firmware · CWE-924 | Критическая9,4 | — | 0,3 % | 25 июл. 2025 г. |
36Наблюдать | CVE-2020-5869Эксплойта нет | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidenf5 · big-iq centralized management · CWE-924 | Критическая9,1 | — | 0,5 % | 24 апр. 2020 г. |
36Наблюдать | CVE-2024-44730Эксплойта нет | Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat CWE-924 | Критическая9,1 | — | 0,4 % | 11 окт. 2024 г. |
35Наблюдать | CVE-2025-0592Эксплойта нет | SICK Lector8xx and InspectorP8xx vulnerable for code executionsick ag · sick lector8xx · CWE-924 | Высокая8,8 | — | 0,4 % | 14 февр. 2025 г. |
35Наблюдать | CVE-2019-25719Эксплойта нет | Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handlingdräger · infinity acute care system · CWE-924 | Высокая8,8 | — | 0,1 % | 2 июн. 2026 г. |
34Наблюдать | CVE-2021-34793Эксплойта нет | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerabilitycisco · adaptive security appliance · CWE-924 | Высокая8,6 | — | 0,6 % | 27 окт. 2021 г. |
32Наблюдать | CVE-2018-7295Эксплойта нет | ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During square-enix · final fantasy xiv · CWE-924 | Высокая8,1 | — | 0,4 % | 23 мая 2018 г. |
32Наблюдать | CVE-2021-41034Эксплойта нет | The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint.eclipse · che · CWE-924 | Высокая8,1 | — | 0,4 % | 29 сент. 2021 г. |
32Наблюдать | CVE-2023-6408Эксплойта нет | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a dschneider-electric · modicon m340 bmxp341000 firmware · CWE-924 | Высокая8,1 | — | 0,3 % | 14 февр. 2024 г. |
32Наблюдать | CVE-2023-2885Эксплойта нет | Channel Accessible by Non-Endpoint in CBOT's Chatbotcbot · cbot core · CWE-924 | Высокая8,1 | — | 0,3 % | 25 мая 2023 г. |
31Наблюдать | CVE-2020-11639Эксплойта нет | Insufficient access control on Inter process communication,abb · advabuild · CWE-924 | Высокая7,8 | — | 0,1 % | 23 июл. 2024 г. |
30Наблюдать | CVE-2022-3166Эксплойта нет | MicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition Attackrockwellautomation · micrologix 1100 firmware · CWE-924 | Высокая7,5 | — | 0,7 % | 16 дек. 2022 г. |
30Наблюдать | CVE-2024-43450Эксплойта нет | Windows DNS Spoofing Vulnerabilitymicrosoft · windows server 2008 · CWE-924 | Высокая7,5 | — | 0,6 % | 12 нояб. 2024 г. |
30Наблюдать | CVE-2023-49933Эксплойта нет | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x.schedmd · slurm · CWE-924 | Высокая7,5 | — | 0,4 % | 14 дек. 2023 г. |
30Наблюдать | CVE-2024-8933Эксплойта нет | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrschneider electric · modicon m340 cpu (part numbers bmxp34*) · CWE-924 | Высокая7,5 | — | 0,3 % | 13 нояб. 2024 г. |
30Наблюдать | CVE-2026-12576Эксплойта нет | DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerabilitydeltaww · dvp80es3 · CWE-924 | Высокая7,5 | — | 0,2 % | 1 июл. 2026 г. |
28Наблюдать | CVE-2026-13584Эксплойта нет | Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocolmitsubishi electric corporation · melsec mx controller mx-r model mxr300-16 · CWE-924 | Высокая7,1 | — | 0,2 % | 30 июл. 2026 г. |
27Наблюдать | GHSA-vhmj-5q9r-mm9gЭксплойта нет | BlastRADIUS also affects eduMFAPyPI · edumfa · CWE-924 | Средняя6,8 | — | — | 17 июл. 2024 г. |
26Наблюдать | CVE-2018-14526Эксплойта нет | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6.canonical · ubuntu linux · CWE-924 | Средняя6,5 | — | 1,5 % | 8 авг. 2018 г. |
26Наблюдать | CVE-2019-20844Эксплойта нет | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7.mattermost · mattermost server · CWE-924 | Средняя6,5 | — | 0,4 % | 19 июн. 2020 г. |
26Наблюдать | CVE-2026-39827Эксплойта нет | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshgolang · crypto · CWE-924 | Средняя6,5 | — | 0,3 % | 22 мая 2026 г. |
25Наблюдать | CVE-2026-54891Эксплойта нет | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslerlang · erlang\/otp · CWE-924 | Средняя6,3 | — | 0,1 % | 2 июл. 2026 г. |
24Наблюдать | CVE-2024-12399Эксплойта нет | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partschneider electric · pro-face gp-pro ex · CWE-924 | Средняя6,1 | — | 0,2 % | 17 янв. 2025 г. |
23Наблюдать | CVE-2021-21390Эксплойта нет | MITM modification of request bodies in MinIOminio · minio · CWE-924 | Средняя5,9 | — | 0,9 % | 19 мар. 2021 г. |
23Наблюдать | CVE-2023-22372Эксплойта нет | BIG-IP Edge Client for Windows and Mac OS vulnerabilityf5 · big-ip access policy manager · CWE-924 | Средняя5,9 | — | 0,2 % | 3 мая 2023 г. |
- CVE-2025-2962837Наблюдать
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home
КритическаяCVSS 9,4Proof of conceptEPSS 0 %gardyn · home kit firmware25 июл. 2025 г.
- CVE-2020-586936Наблюдать
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confiden
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %f5 · big-iq centralized management24 апр. 2020 г.
- CVE-2024-4473036Наблюдать
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %11 окт. 2024 г.
- CVE-2025-059235Наблюдать
SICK Lector8xx and InspectorP8xx vulnerable for code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sick ag · sick lector8xx14 февр. 2025 г.
- CVE-2019-2571935Наблюдать
Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %dräger · infinity acute care system2 июн. 2026 г.
- CVE-2021-3479334Наблюдать
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Transparent Mode Denial of Service Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %cisco · adaptive security appliance27 окт. 2021 г.
- CVE-2018-729532Наблюдать
ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %square-enix · final fantasy xiv23 мая 2018 г.
- CVE-2021-4103432Наблюдать
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %eclipse · che29 сент. 2021 г.
- CVE-2023-640832Наблюдать
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a d
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %schneider-electric · modicon m340 bmxp341000 firmware14 февр. 2024 г.
- CVE-2023-288532Наблюдать
Channel Accessible by Non-Endpoint in CBOT's Chatbot
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %cbot · cbot core25 мая 2023 г.
- CVE-2020-1163931Наблюдать
Insufficient access control on Inter process communication,
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %abb · advabuild23 июл. 2024 г.
- CVE-2022-316630Наблюдать
MicroLogix 1100 & 1400 Product Web Server Application Vulnerable to Denial-Of-Service Condition Attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rockwellautomation · micrologix 1100 firmware16 дек. 2022 г.
- CVE-2024-4345030Наблюдать
Windows DNS Spoofing Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microsoft · windows server 200812 нояб. 2024 г.
- CVE-2023-4993330Наблюдать
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %schedmd · slurm14 дек. 2023 г.
- CVE-2024-893330Наблюдать
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retr
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %schneider electric · modicon m340 cpu (part numbers bmxp34*)13 нояб. 2024 г.
- CVE-2026-1257630Наблюдать
DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %deltaww · dvp80es31 июл. 2026 г.
- CVE-2026-1358428Наблюдать
Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %mitsubishi electric corporation · melsec mx controller mx-r model mxr300-1630 июл. 2026 г.
- GHSA-vhmj-5q9r-mm9g27Наблюдать
BlastRADIUS also affects eduMFA
СредняяCVSS 6,8Эксплойта нетPyPI · edumfa17 июл. 2024 г.
- CVE-2018-1452626Наблюдать
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %canonical · ubuntu linux8 авг. 2018 г.
- CVE-2019-2084426Наблюдать
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %mattermost · mattermost server19 июн. 2020 г.
- CVE-2026-3982726Наблюдать
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
СредняяCVSS 6,5Эксплойта нетEPSS 0 %golang · crypto22 мая 2026 г.
- CVE-2026-5489125Наблюдать
Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
СредняяCVSS 6,3Эксплойта нетEPSS 0 %erlang · erlang\/otp2 июл. 2026 г.
- CVE-2024-1239924Наблюдать
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause part
СредняяCVSS 6,1Эксплойта нетEPSS 0 %schneider electric · pro-face gp-pro ex17 янв. 2025 г.
- CVE-2021-2139023Наблюдать
MITM modification of request bodies in MinIO
СредняяCVSS 5,9Эксплойта нетEPSS 1 %minio · minio19 мар. 2021 г.
- CVE-2023-2237223Наблюдать
BIG-IP Edge Client for Windows and Mac OS vulnerability
СредняяCVSS 5,9Эксплойта нетEPSS 0 %f5 · big-ip access policy manager3 мая 2023 г.