CWE-347— Improper Verification of Cryptographic Signature
627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 6 of 13
- CVE-2021-37127HIGHCVSS 7.2EG 7.22021-10-27
There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file o…
- CVE-2021-37160CRITICALCVSS 9.8EG 9.82021-08-02
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature val…
- CVE-2021-37927CRITICALCVSS 9.8EG 9.82021-09-22
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- CVE-2021-38195CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.
- CVE-2021-39909MEDIUMCVSS 5.3EG 5.32021-11-05
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a…
- CVE-2021-40045MEDIUMCVSS 5.5EG 5.52022-02-09
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-40326MEDIUMCVSS 5.5EG 5.52022-08-29
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature…
- CVE-2021-41830HIGHCVSS 7.5EG 7.52021-10-11
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-2563…
- CVE-2021-41831MEDIUMCVSS 5.3EG 5.32021-10-11
It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.
- CVE-2021-41832HIGHCVSS 7.5EG 7.52021-10-11
It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the Libre…
- CVE-2021-43074MEDIUMCVSS 4.3EG 4.32023-02-16
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versions, 6.1 all versions, 6.0 all versions; FortiOS 7.0.3 and below, 6.4.8 and below, 6.2 all versions, …
- CVE-2021-43171MEDIUMCVSS 6.5EG 6.52023-08-22
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the…
- CVE-2021-43392MEDIUMCVSS 6.2EG 6.22022-03-04
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms ex…
- CVE-2021-43393MEDIUMCVSS 6.2EG 6.22022-03-04
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 …
- CVE-2021-43568CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43569CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43570CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43571CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43572CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-44878HIGHCVSS 7.5EG 7.52022-01-06
If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its side or for the "idtoken" response type which is not secure …
- CVE-2022-1739MEDIUMCVSS 6.8EG 7.62022-06-24
The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable again…
- CVE-2022-20929HIGHCVSS 7.8EG 7.82023-03-10
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to …
- CVE-2022-20944MEDIUMCVSS 6.1EG 6.82022-10-10
A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerab…
- CVE-2022-21134HIGHCVSS 7.5EG 7.52022-01-28
A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of reques…
- CVE-2022-23334CRITICALCVSS 9.8EG 9.82023-01-30
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
- CVE-2022-23507MEDIUMCVSS 5.4EG 5.42022-12-15
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the te…
- CVE-2022-23540MEDIUMCVSS 6.4EG 6.42022-12-22
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected i…
- CVE-2022-23610CRITICALCVSS 9.1EG 9.12022-03-16
wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possible to craft DSA Signatures to bypass SAML SSO and impersonate any Wire user with SAML crede…
- CVE-2022-23655MEDIUMCVSS 4.8EG 4.82022-02-24
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private k…
- CVE-2022-24115HIGHCVSS 7.8EG 7.82022-02-04
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287
- CVE-2022-24759HIGHCVSS 8.1EG 8.12022-03-17
`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. Th…
- CVE-2022-24771HIGHCVSS 7.5EG 7.52022-03-18
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allo…
- CVE-2022-24772HIGHCVSS 7.5EG 7.52022-03-18
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInf…
- CVE-2022-24773MEDIUMCVSS 5.3EG 5.32022-03-18
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. T…
- CVE-2022-24884CRITICALCVSS 10.0EG 10.02022-05-06
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always cons…
- CVE-2022-25333HIGHCVSS 8.2EG 8.22023-10-19
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routine. However, only the module header authenticity is validate…
- CVE-2022-25898HIGHCVSS 7.7EG 7.72022-07-01
The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mist…
- CVE-2022-26510MEDIUMCVSS 6.5EG 6.52022-05-12
A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger …
- CVE-2022-2790MEDIUMCVSS 5.9EG 5.92022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).
- CVE-2022-28751HIGHCVSS 8.8EG 7.82022-08-17
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability t…
- CVE-2022-28752HIGHCVSS 8.8EG 7.82022-08-17
Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SY…
- CVE-2022-28756HIGHCVSS 8.8EG 7.82022-08-15
The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate …
- CVE-2022-31053CRITICALCVSS 9.8EG 9.82022-06-13
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow…
- CVE-2022-31123MEDIUMCVSS 6.1EG 6.12022-10-13
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successful…
- CVE-2022-31156MEDIUMCVSS 6.6EG 6.62022-07-14
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through …
- CVE-2022-31172HIGHCVSS 7.5EG 7.52022-07-22
OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignatureNow` is not expected to revert. However, an incorrect assump…
- CVE-2022-31206CRITICALCVSS 9.8EG 9.82022-07-26
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 611…
- CVE-2022-31207CRITICALCVSS 9.8EG 9.82022-07-26
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects an…
- CVE-2022-31807MEDIUMCVSS 6.2EG 6.22025-05-23
A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a malicious…
- CVE-2022-3322MEDIUMCVSS 6.7EG 6.72022-10-28
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →