Skip to main content

Missing Support for Integrity Check

CVE-2021-38396

Severity Medium
Score 6.5/10

Summary

The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.

  • LOW
  • PHYSICAL
  • HIGH
  • CHANGED
  • REQUIRED
  • NONE
  • LOW
  • LOW

CWE-353 - Missing Support for Integrity Check

The software uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.

References

Advisory Timeline

  • Published