CWE-354Base

Improper Validation of Integrity Check Value

Draft in the CWE catalog · 95 CVEs mapped

95
CVEs mapped
7.5
Median CVSS
What it is

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Recent examples
5.9cvss
CVE-2026-20354

CVE-2026-20354 - MEDIUM Severity Vulnerability

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

MEDIUMno explanation yet
0%
epss
8.3cvss
CVE-2026-82549

CVE-2026-82549 - HIGH Severity Vulnerability

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2025-61480

CVE-2025-61480 - HIGH Severity Vulnerability

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-354
Abstraction
Base
Structure
Simple
Status
Draft
References (1)