CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.
24 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-0592 — SICK Lector8xx and InspectorP8xx vulnerable for code execution
- CVE-2019-25719 — Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
- CVE-2024-12399 — CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t
- CVE-2026-48106 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
- CVE-2026-12576 — DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
- CVE-2026-13584 — Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
- CVE-2026-54891 — Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
- CVE-2024-52288 — RMAC revert to the beginning of the session in libosdp
- CVE-2026-14681 — PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
- CVE-2026-68554 — Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
Recently published
- CVE-2026-48106 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
- CVE-2026-68554 — Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
- CVE-2026-14681 — PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
- CVE-2026-13584 — Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
- CVE-2026-54891 — Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
- CVE-2026-12576 — DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
- CVE-2019-25719 — Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
- CVE-2025-0592 — SICK Lector8xx and InspectorP8xx vulnerable for code execution
- CVE-2024-12399 — CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t
- CVE-2024-52288 — RMAC revert to the beginning of the session in libosdp