Missing Support for Integrity Check
CVE-2021-38396
Summary
The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.
- LOW
- PHYSICAL
- HIGH
- CHANGED
- REQUIRED
- NONE
- LOW
- LOW
CWE-353 - Missing Support for Integrity Check
The software uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.
References
Advisory Timeline
- Published