What is CWE-345?
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-345 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: ICS/OT.
Source: MITRE CWE (CWE-345 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Other — Varies by Context, Unexpected State
Source: MITRE CWE, common consequences.
How CWE-345 is exploited in the wild
Threadlinqs maps 12 CVEs to CWE-345, published between 2023-08-23 and 2026-10-04. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 5 high, 6 medium. The highest EPSS score in the set is 93.8% (CVE-2023-38831), the modelled probability of exploitation in the next 30 days. 48 tracked threats reference CWE-345 directly or through a CVE it covers; the most recent is “Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse” (2026-09-25). Affected products concentrate in CoreWCF (3), AMD (1), Rarlab (1), among 10 vendors in total.
Vulnerabilities (CVEs)
All 12 CVEs mapped to CWE-345, CISA KEV first, then by CVSS score.
- CVE-2023-38831 — CISA KEV · CVSS 7.8 high · EPSS 93.8% · published 2023-08-23
- CVE-2026-27510 — CVSS 9.6 critical · EPSS 0.2% · published 2026-02-26
- CVE-2023-20576 — CVSS 7.7 high · EPSS 0.1% · published 2026-09-02
- CVE-2026-54781 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-54774 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-54783 — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-73840 — CVSS 5.3 medium · EPSS 0.2% · published 2026-08-13
- CVE-2026-105161 — CVSS 5.3 medium · published 2026-10-04
- CVE-2026-44434 — CVSS 5.3 medium · published 2026-07-16
- CVE-2026-9242 — CVSS 5.3 medium · published 2026-06-27
- CVE-2026-13507 — CVSS 5 medium · EPSS 0.1% · published 2026-06-28
- CVE-2026-73657 — CVSS 4.2 medium · EPSS 0.1% · published 2026-08-13
Affected vendors
- CoreWCF — 3 CVEs
- AMD — 1 CVE
- Rarlab — 1 CVE
- UnitreeRobotics — 1 CVE
- h2o — 1 CVE
- invariant-systems-ai — 1 CVE
- metagauss — 1 CVE
- openchoreo — 1 CVE
- triggerdotdev — 1 CVE
- volcengine — 1 CVE
Threat activity
48 tracked threats cite CWE-345; the 25 most recent are listed.
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow AbuseCRITICAL
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)CRITICAL
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX BotnetHIGH
- Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card PurchasesHIGH
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and KimiHIGH
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply ChainHIGH
- Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield MalwareHIGH
- RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and SharePoint DataCRITICAL
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI ApplicationsMEDIUM
- CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis SoftwareHIGH
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027)HIGH
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)MEDIUM
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)HIGH
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)CRITICAL
- Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179)HIGH
- HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill NamesMEDIUM
- GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing, Local Secret Disclosure, and Path Traversal (CVE Pending)HIGH
- Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat Campaigns)MEDIUM
- Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines (Microsoft Azure Sentinel, Google ADK, Apache Doris, Cloudflare Workers SDK, PSF Black)CRITICAL
- Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model Hijacking and RCEHIGH
- Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE (google-cloud-aiplatform v1.139.0/v1.140.0)HIGH
- Maine AG Data Breach Notification Portal Abused to Publish Fraudulent Breach Disclosures Impersonating VRChat and DiscordMEDIUM
- OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock InvestorsHIGH
- CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)HIGH
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.