CWE-649: Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified.
5 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10772 — SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification
- CVE-2025-5323 — fossasia open-event-server Mail Verification mail.py send_email_change_user_email reliance on obfuscation or encryption of security-relevant inputs without integrity checking
- CVE-2025-41351 — Weak encryption on Funambol's cloud server
Recently published
- CVE-2025-41351 — Weak encryption on Funambol's cloud server
- CVE-2025-5323 — fossasia open-event-server Mail Verification mail.py send_email_change_user_email reliance on obfuscation or encryption of security-relevant inputs without integrity checking
- CVE-2024-10772 — SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification