CWE-353Base

Missing Support for Integrity Check

Draft in the CWE catalog · 37 CVEs mapped

37
CVEs mapped
6.7
Median CVSS
What it is

The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.

Recent examples
6.5cvss
CVE-2026-58224

CVE-2026-58224 - MEDIUM Severity Vulnerability

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.

MEDIUMno explanation yet
0%
epss
8.4cvss
CVE-2026-17583

CVE-2026-17583 - HIGH Severity Vulnerability

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2026-18536

CVE-2026-18536 - HIGH Severity Vulnerability

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-353
Abstraction
Base
Structure
Simple
Status
Draft
References (1)