目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-353 缺失完整性检查支持 类漏洞列表 38

CWE-353 缺失完整性检查支持 类弱点 38 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-353 指产品在使用传输协议时,缺乏校验和等数据完整性验证机制。攻击者常利用此缺陷在传输过程中篡改数据,而接收方无法察觉内容是否被恶意修改或损坏。开发者应避免使用无完整性保护的协议,或在应用层引入哈希校验、数字签名等机制,确保数据在传输前后的完整性,从而有效防范数据篡改风险。

MITRE CWE 官方描述
CWE:CWE-353 Missing Support for Integrity Check 英文:The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum. 如果协议中省略了完整性检查值(integrity check values)或“校验和”(checksums),则无法确定数据在传输过程中是否已损坏。协议中缺乏校验和(checksum)功能,意味着移除了第一个可用的应用程序级数据检查。端到端(end-to-end)的检查原则指出,完整性检查(integrity checks)应在能够完全实现的最低层级执行。排除应用程序执行的进一步健全性检查(sanity checks)和输入验证(input validation),协议的校验和(checksum)是最重要的一层校验,因为它比任何先前层级都能更完整地执行,并且考虑的是整个消息(entire messages),而非单个数据包(single packets)。
常见影响 (2)
Integrity, Other Other
Data that is parsed and used may be corrupted.
Non-Repudiation, Other Hide Activities, Other
Without a checksum it is impossible to determine if any changes have been made to the data after it was sent.
缓解措施 (2)
Architecture and Design Add an appropriately sized checksum to the protocol, ensuring that data received may be simply validated before it is parsed and used.
Implementation Ensure that the checksums present in the protocol design are properly implemented and added to each message before it is sent.
代码示例 (1)
In this example, a request packet is received, and privileged information is sent to the requester:
while(true) { DatagramPacket rp = new DatagramPacket(rData,rData.length); outSock.receive(rp); InetAddress IPAddress = rp.getAddress(); int port = rp.getPort(); out = secret.getBytes(); DatagramPacket sp =new DatagramPacket(out, out.length, IPAddress, port); outSock.send(sp); }
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-76853 Netcore NR268 1.7.121109 安全校验绕过漏洞 — NR268 8.1 High 2026-09-15
CVE-2026-89179 Howyar WeenyGenius 加密问题漏洞 — WeenyGenius 4.3 Medium 2026-09-11
CVE-2026-81049 Dell ThinOS 10 加密问题漏洞 — ThinOS 10 4.4 Medium 2026-09-10
CVE-2026-58224 Samba CTDB 加密问题漏洞 — Red Hat Enterprise Linux 10 6.5 Medium 2026-08-14
CVE-2026-17583 Thermo Fisher Scientific Applied Biosystems Genetic Analyzers 加密问题漏洞 — Applied Biosystems 3500/3500xL Series Data Collection Software 8.4 High 2026-08-05
CVE-2026-12705 ABB KNX Update Tool 加密问题漏洞 — KNX Update Tool (ABB) 6.4 Medium 2026-07-17
CVE-2026-48995 pnpm 加密问题漏洞 — pnpm - - 2026-06-25
CVE-2026-7574 Anthropic Claude Desktop Cowork 加密问题漏洞 — Claude Desktop Cowork 8.7 High 2026-06-23
CVE-2026-42428 OpenClaw 安全漏洞 — OpenClaw 7.1 High 2026-04-28
CVE-2026-3856 IBM DB2 Recovery Expert 安全漏洞 — Db2 Recovery Expert 5.3 Medium 2026-03-17
CVE-2025-10010 CPSD CryptoPro Secure Disk 安全漏洞 — CryptoPro Secure Disk for BitLocker 7.1AI High AI 2026-02-24
CVE-2025-15364 WordPress plugin Download Manager 安全漏洞 — Download Manager 7.3 High 2026-01-06
CVE-2026-21437 eopkg 安全漏洞 — eopkg 3.7 - 2026-01-01
CVE-2025-48500 F5 BIG-IP Edge Client 安全漏洞 — BIG-IP Edge Client 7.3 High 2025-08-13
CVE-2025-48811 Microsoft Windows Virtualization-Based Security Enclave 安全漏洞 — Windows 10 Version 1507 6.7 Medium 2025-07-08
CVE-2025-48803 Microsoft Windows Virtualization-Based Security Enclave 安全漏洞 — Windows 10 Version 1507 6.7 Medium 2025-07-08
CVE-2024-43108 goTenna Pro 安全漏洞 — Pro ATAK Plugin 5.3 Medium 2024-09-26
CVE-2024-47123 goTenna Pro 安全漏洞 — Pro 5.3 Medium 2024-09-26
CVE-2023-32475 Dell BIOS 安全漏洞 — CPG BIOS 7.6 High 2024-06-07
CVE-2022-24404 TETRA BURST 安全漏洞 — TETRA Standard 5.9 Medium 2023-10-19
CVE-2023-29290 Adobe Commerce 安全漏洞 — Magento Commerce 5.3 Medium 2023-06-15
CVE-2022-2793 Emerson Proficy Machine Edition 数据伪造问题漏洞 — Proficy Machine Edition 5.9 Medium 2022-08-19
CVE-2020-7878 VideoOffice 数据伪造问题漏洞 — VideoOffice 9.8 - 2021-12-28
CVE-2021-26610 Nhn Commerce Godomall5 数据伪造问题漏洞 — godomall5 Std, godomall5 Pro 7.2 High 2021-10-27
CVE-2021-38396 Boston Scientific Zoom Latitude Programmer/Recorder/Monitor Model 3120 数据伪造问题漏洞 — ZOOM LATITUDE 6.5 Medium 2021-10-04
CVE-2021-26608 Handysoft 数据伪造问题漏洞 — HShell.dll 8.8 High 2021-09-09
CVE-2021-28546 Adobe Acrobat Reader DC 安全漏洞 — Acrobat Reader 6.5 Medium 2021-04-01
CVE-2021-28545 Adobe Acrobat Reader 安全漏洞 — Acrobat Reader 8.1 High 2021-04-01
CVE-2020-7807 LG 安全漏洞 — (LGPCSuite_Setup), (IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) 5.6 Medium 2020-09-14
CVE-2020-9062 Diebold Nixdorf 2100xe USB ATMs 访问控制错误漏洞 — ProCash 2100xe USB ATM 5.3 - 2020-08-21

CWE-353(缺失完整性检查支持) 是常见的弱点类别,本平台收录该类弱点关联的 38 条 CVE 漏洞。