CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
742 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 6 of 15
- CVE-2021-33885CRITICALCVSS 10.0EG 10.02021-08-25
An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This resul…
- CVE-2021-3406CRITICALCVSS 9.8EG 9.82021-02-25
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
- CVE-2021-3421MEDIUMCVSS 5.5EG 5.52021-05-19
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest …
- CVE-2021-34420MEDIUMCVSS 4.7EG 4.72021-11-11
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer�…
- CVE-2021-34433HIGHCVSS 7.5EG 7.52021-08-20
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not i…
- CVE-2021-3445HIGHCVSS 7.5EG 7.52021-05-19
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system …
- CVE-2021-34708MEDIUMCVSS 6.0EG 6.02021-09-09
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow…
- CVE-2021-34709MEDIUMCVSS 6.0EG 6.02021-09-09
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow…
- CVE-2021-34715MEDIUMCVSS 4.7EG 4.72021-08-18
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underl…
- CVE-2021-35039HIGHCVSS 7.8EG 7.82021-07-07
kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.si…
- CVE-2021-35097HIGHCVSS 7.3EG 7.32022-09-02
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial I…
- CVE-2021-35113HIGHCVSS 7.3EG 7.32022-09-02
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Sn…
- CVE-2021-3521MEDIUMCVSS 4.7EG 4.72022-08-22
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or so…
- CVE-2021-36226CRITICALCVSS 9.8EG 9.82023-02-06
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
- CVE-2021-36277HIGHCVSS 7.8EG 7.82021-08-09
Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbit…
- CVE-2021-3633HIGHCVSS 7.3EG 7.82021-08-17
A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.
- CVE-2021-3680MEDIUMCVSS 4.9EG 4.92021-08-04
showdoc is vulnerable to Missing Cryptographic Step
- CVE-2021-37127HIGHCVSS 7.2EG 7.22021-10-27
There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file o…
- CVE-2021-37160CRITICALCVSS 9.8EG 9.82021-08-02
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature val…
- CVE-2021-37927CRITICALCVSS 9.8EG 9.82021-09-22
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- CVE-2021-38195CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.
- CVE-2021-39909MEDIUMCVSS 5.3EG 5.32021-11-05
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a…
- CVE-2021-40045MEDIUMCVSS 5.5EG 5.52022-02-09
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-40326MEDIUMCVSS 5.5EG 5.52022-08-29
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature…
- CVE-2021-41830HIGHCVSS 7.5EG 7.52021-10-11
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-2563…
- CVE-2021-41831MEDIUMCVSS 5.3EG 5.32021-10-11
It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.
- CVE-2021-41832HIGHCVSS 7.5EG 7.52021-10-11
It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the Libre…
- CVE-2021-43074MEDIUMCVSS 4.3EG 4.32023-02-16
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, …
- CVE-2021-43171MEDIUMCVSS 6.5EG 6.52023-08-22
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the…
- CVE-2021-43392MEDIUMCVSS 6.2EG 6.22022-03-04
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms ex…
- CVE-2021-43393MEDIUMCVSS 6.2EG 6.22022-03-04
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 …
- CVE-2021-43568CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43569CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43570CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43571CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43572CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-44878HIGHCVSS 7.5EG 7.52022-01-06
If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its side or for the "idtoken" response type which is not secure …
- CVE-2022-1739HIGHCVSS 6.8EG 7.62022-06-24
The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable again…
- CVE-2022-20929HIGHCVSS 7.8EG 7.82023-03-10
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to …
- CVE-2022-20944MEDIUMCVSS 6.1EG 6.82022-10-10
A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerab…
- CVE-2022-21134HIGHCVSS 7.5EG 7.52022-01-28
A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of reques…
- CVE-2022-23334CRITICALCVSS 9.8EG 9.82023-01-30
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
- CVE-2022-23507MEDIUMCVSS 5.4EG 5.42022-12-15
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the te…
- CVE-2022-23540MEDIUMCVSS 6.4EG 6.42022-12-22
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected i…
- CVE-2022-23610CRITICALCVSS 9.1EG 9.12022-03-16
wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possible to craft DSA Signatures to bypass SAML SSO and impersonate any Wire user with SAML crede…
- CVE-2022-23655MEDIUMCVSS 4.8EG 4.82022-02-24
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private k…
- CVE-2022-24115HIGHCVSS 7.8EG 7.82022-02-04
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287
- CVE-2022-24759HIGHCVSS 8.1EG 8.12022-03-17
`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. Th…
- CVE-2022-24771HIGHCVSS 7.5EG 7.52022-03-18
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allo…
- CVE-2022-24772HIGHCVSS 7.5EG 7.52022-03-18
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInf…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →