CWE Database
/

CWE-345

Back to CWE list

CWE-345

Insufficient Verification of Data Authenticity

Class
Draft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Parent Weaknesses (ChildOf)

Common Consequences

Scope

Integrity
Other

Impact

Varies by Context, Unexpected State

CVE-2022-30260

Distributed Control System (DCS) does not sign firmware images and only relies on insecure checksums for integrity checks

CVE-2022-30267

Distributed Control System (DCS) does not sign firmware images and only relies on insecure checksums for integrity checks

CVE-2022-30272

Remote Terminal Unit (RTU) does not use signatures for firmware images and relies on insecure checksums

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now