CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
742 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 5 of 15
- CVE-2020-8133MEDIUMCVSS 5.3EG 5.32020-11-09
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
- CVE-2020-8324MEDIUMCVSS 5.0EG 5.02020-04-14
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.
- CVE-2020-9047MEDIUMCVSS 6.8EG 6.82020-06-26
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior…
- CVE-2020-9226MEDIUMCVSS 5.5EG 5.52020-07-06
HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to …
- CVE-2020-9283HIGHCVSS 7.5EG 7.52020-02-20
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack…
- CVE-2020-9753CRITICALCVSS 9.1EG 9.12020-05-20
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
- CVE-2021-0152MEDIUMCVSS 5.5EG 5.52021-11-17
Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local …
- CVE-2021-1136MEDIUMCVSS 6.7EG 6.72021-02-04
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local …
- CVE-2021-1244MEDIUMCVSS 6.7EG 6.72021-02-04
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local …
- CVE-2021-1366HIGHCVSS 7.8EG 7.82021-02-17
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture …
- CVE-2021-1375MEDIUMCVSS 6.7EG 6.72021-03-24
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbit…
- CVE-2021-1376MEDIUMCVSS 6.7EG 6.72021-03-24
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbit…
- CVE-2021-1453MEDIUMCVSS 6.8EG 6.82021-03-24
A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. The vu…
- CVE-2021-1461MEDIUMCVSS 4.9EG 4.92024-11-18
A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device. The …
- CVE-2021-1849HIGHCVSS 7.5EG 7.52021-09-08
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.
- CVE-2021-20156MEDIUMCVSS 6.5EG 6.52021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not ap…
- CVE-2021-20319HIGHCVSS 7.8EG 7.82022-03-04
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. …
- CVE-2021-20487CRITICALCVSS 9.1EG 9.12021-05-26
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
- CVE-2021-21238MEDIUMCVSS 6.5EG 6.52021-01-21
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. …
- CVE-2021-21239MEDIUMCVSS 6.5EG 6.52021-01-21
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to …
- CVE-2021-21405MEDIUMCVSS 5.9EG 5.92021-04-15
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized", and "compressed", meaning that BLS sig…
- CVE-2021-21474MEDIUMCVSS 6.5EG 6.52021-02-09
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that t…
- CVE-2021-22160CRITICALCVSS 9.8EG 9.82021-05-26
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to…
- CVE-2021-22573HIGHCVSS 8.7EG 8.72022-05-03
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised toke…
- CVE-2021-22708HIGHCVSS 7.2EG 7.22021-07-21
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Sma…
- CVE-2021-22734HIGHCVSS 7.2EG 7.22021-05-26
Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code.
- CVE-2021-22735HIGHCVSS 7.2EG 7.22021-05-26
Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.
- CVE-2021-23992MEDIUMCVSS 4.3EG 4.32021-06-24
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thun…
- CVE-2021-23993MEDIUMCVSS 6.5EG 6.52021-06-24
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the cra…
- CVE-2021-24020CRITICALCVSS 7.5EG 9.82021-07-09
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allo…
- CVE-2021-25636HIGHCVSS 7.5EG 7.52022-02-24
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Valida…
- CVE-2021-26100HIGHCVSS 5.9EG 7.52021-07-09
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the r…
- CVE-2021-26391HIGHCVSS 7.8EG 7.82022-11-09
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.
- CVE-2021-28091HIGHCVSS 7.5EG 7.52021-06-04
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
- CVE-2021-29108HIGHCVSS 8.8EG 8.82021-10-01
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impers…
- CVE-2021-29451CRITICALCVSS 9.1EG 9.12021-04-16
Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens. This allows forging a valid JWT. The issue will be patched in the upcoming 5.2.1 release.
- CVE-2021-29455HIGHCVSS 7.5EG 7.52021-04-19
Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform before master deployment as of 2021-04-16 did not properly verify the sig…
- CVE-2021-29500HIGHCVSS 7.5EG 7.52021-06-04
bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. Th…
- CVE-2021-30066MEDIUMCVSS 6.8EG 6.82022-04-03
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick)…
- CVE-2021-30130HIGHCVSS 7.5EG 7.52021-04-06
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
- CVE-2021-30246CRITICALCVSS 9.1EG 9.12021-04-07
In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.
- CVE-2021-3033CRITICALCVSS 9.1EG 9.12021-02-10
An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in…
- CVE-2021-3051HIGHCVSS 8.1EG 8.12021-09-08
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected re…
- CVE-2021-31841HIGHCVSS 8.2EG 8.22021-09-22
A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gai…
- CVE-2021-31847HIGHCVSS 8.2EG 8.22021-09-22
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and t…
- CVE-2021-3196HIGHCVSS 8.8EG 8.82021-06-09
An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity management (authenticating via SAML through a third-party identity provider), an attacker…
- CVE-2021-32685CRITICALCVSS 9.8EG 9.82021-06-16
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigning…
- CVE-2021-32738MEDIUMCVSS 6.5EG 6.52021-07-02
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the cha…
- CVE-2021-32977HIGHCVSS 7.2EG 7.22022-04-04
AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.
- CVE-2021-33054HIGHCVSS 7.5EG 7.52021-06-04
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (On…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →