CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
743 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 8 of 15
- CVE-2023-23435MEDIUMCVSS 4.0EG 4.02023-12-29
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
- CVE-2023-23436HIGHCVSS 7.3EG 7.32023-12-29
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
- CVE-2023-23772HIGHCVSS 7.2EG 7.22023-08-29
Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code e…
- CVE-2023-23773HIGHCVSS 7.2EG 7.22023-08-29
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, ex…
- CVE-2023-23928MEDIUMCVSS 5.9EG 5.92023-02-01
reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could ex…
- CVE-2023-23940MEDIUMCVSS 6.4EG 6.42023-02-03
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signatu…
- CVE-2023-24025HIGHCVSS 7.5EG 7.52023-01-20
CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.
- CVE-2023-25574CRITICALCVSS 10.0EG 10.02025-02-25
`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allo…
- CVE-2023-25718CRITICALCVSS 9.8EG 9.82023-02-13
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end …
- CVE-2023-25934MEDIUMCVSS 5.9EG 5.92023-05-04
DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the …
- CVE-2023-28113MEDIUMCVSS 5.9EG 5.92023-03-16
russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentialit…
- CVE-2023-28226MEDIUMCVSS 5.3EG 5.32023-04-11
Windows Enroll Engine Security Feature Bypass Vulnerability
- CVE-2023-28228MEDIUMCVSS 5.5EG 5.52023-04-11
Windows Spoofing Vulnerability
- CVE-2023-28602LOWCVSS 2.8EG 2.82023-06-13
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.
- CVE-2023-28610CRITICALCVSS 9.8EG 9.82023-03-23
The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.
- CVE-2023-28796HIGHCVSS 7.1EG 7.12023-10-23
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- CVE-2023-28801CRITICALCVSS 9.6EG 9.62023-08-31
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
- CVE-2023-28804HIGHCVSS 8.2EG 8.22023-10-23
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105
- CVE-2023-28806MEDIUMCVSS 5.7EG 5.72024-08-06
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.
- CVE-2023-28818MEDIUMCVSS 5.3EG 5.32023-03-24
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could…
- CVE-2023-32449HIGHCVSS 7.2EG 7.22023-06-22
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature …
- CVE-2023-33185MEDIUMCVSS 4.6EG 4.62023-05-26
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS t…
- CVE-2023-3347MEDIUMCVSS 5.9EG 5.92023-07-20
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is manda…
- CVE-2023-33768MEDIUMCVSS 6.5EG 6.52023-07-13
Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file.
- CVE-2023-33959HIGHCVSS 8.3EG 8.32023-06-06
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify the wrong artifact. The problem has been fixed in the release v1.0.0-rc.6. Users should upgr…
- CVE-2023-34058HIGHCVSS 7.1EG 7.52023-10-27
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643E…
- CVE-2023-34120HIGHCVSS 8.7EG 8.72023-06-13
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potenti…
- CVE-2023-34205CRITICALCVSS 9.1EG 9.12023-05-30
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).
- CVE-2023-34435HIGHCVSS 7.2EG 7.22024-07-08
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malicious file to trigge…
- CVE-2023-35373MEDIUMCVSS 5.3EG 5.32023-07-11
Mono Authenticode Validation Spoofing Vulnerability
- CVE-2023-36811MEDIUMCVSS 4.7EG 4.72023-08-30
borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptographic authentication scheme in borgbackup allowed an attacker to fake archives and potentially indirectly cause backup…
- CVE-2023-38418HIGHCVSS 7.8EG 7.82023-08-02
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-39211HIGHCVSS 8.8EG 8.82023-08-08
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.
- CVE-2023-39392HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.
- CVE-2023-39393HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
- CVE-2023-39969CRITICALCVSS 9.0EG 9.02023-08-09
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sections by virtual address, in violation of the Authenticode sp…
- CVE-2023-40012MEDIUMCVSS 5.9EG 5.92023-08-09
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.50…
- CVE-2023-40178MEDIUMCVSS 5.3EG 5.32023-08-23
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could…
- CVE-2023-40727HIGHCVSS 7.8EG 7.82023-09-12
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism. This could allow an attacker to tamper the application code.
- CVE-2023-41037MEDIUMCVSS 4.3EG 4.32023-08-29
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools. These messages typical…
- CVE-2023-41337MEDIUMCVSS 6.7EG 6.72023-12-12
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple addresses or ports with each of them using different backend servers managed by multiple ent…
- CVE-2023-41744HIGHCVSS 7.8EG 7.82023-08-31
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) before build 30600, Acronis Cyber Protect 15 (macOS) before build 35979.
- CVE-2023-41764MEDIUMCVSS 5.5EG 5.52023-09-12
Microsoft Office Spoofing Vulnerability
- CVE-2023-42806MEDIUMCVSS 6.5EG 6.52023-09-21
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of this head) to use a snapshot from an old head instance with the…
- CVE-2023-42811MEDIUMCVSS 5.5EG 5.52023-09-22
aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even…
- CVE-2023-43611HIGHCVSS 7.8EG 7.82023-10-10
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. This vulnerability is due to an incomplete fix for CVE-2023-38418. Note: Software versions which have …
- CVE-2023-43660HIGHCVSS 8.1EG 8.12023-09-27
Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be bypassed by sending an SSH key offer without a signature. This allows bypassing authenticatio…
- CVE-2023-44077CRITICALCVSS 9.8EG 9.82024-01-17
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
- CVE-2023-46234HIGHCVSS 7.5EG 7.52023-10-26
browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to co…
- CVE-2023-46324HIGHCVSS 7.5EG 7.52023-10-23
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUC…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →