Threadlinqs IntelligenceStart free

Weakness · ClassCWE-345

CWE-345: Insufficient Verification of Data Authenticity

KEV-linkedClass

As of 2026-10-05, CWE-345 (Insufficient Verification of Data Authenticity) underlies 12 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 48 tracked threats.

CVEs
12Mapped to CWE-345
CISA KEV
1Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
48Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-345?

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-345 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: ICS/OT.

Source: MITRE CWE (CWE-345 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Other — Varies by Context, Unexpected State

Source: MITRE CWE, common consequences.

How CWE-345 is exploited in the wild

Threadlinqs maps 12 CVEs to CWE-345, published between 2023-08-23 and 2026-10-04. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 5 high, 6 medium. The highest EPSS score in the set is 93.8% (CVE-2023-38831), the modelled probability of exploitation in the next 30 days. 48 tracked threats reference CWE-345 directly or through a CVE it covers; the most recent is “Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse” (2026-09-25). Affected products concentrate in CoreWCF (3), AMD (1), Rarlab (1), among 10 vendors in total.

Vulnerabilities (CVEs)

All 12 CVEs mapped to CWE-345, CISA KEV first, then by CVSS score.

Affected vendors

  • CoreWCF — 3 CVEs
  • AMD — 1 CVE
  • Rarlab — 1 CVE
  • UnitreeRobotics — 1 CVE
  • h2o — 1 CVE
  • invariant-systems-ai — 1 CVE
  • metagauss — 1 CVE
  • openchoreo — 1 CVE
  • triggerdotdev — 1 CVE
  • volcengine — 1 CVE

Threat activity

48 tracked threats cite CWE-345; the 25 most recent are listed.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.