CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
743 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 9 of 15
- CVE-2023-47122MEDIUMCVSS 5.3EG 5.32023-11-10
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instead of through the local TUF client. If the upstream Rekor ser…
- CVE-2023-49079HIGHCVSS 7.5EG 7.52023-11-29
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.
- CVE-2023-49646MEDIUMCVSS 6.5EG 6.52023-12-13
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
- CVE-2023-50228HIGHCVSS 7.8EG 7.82024-05-03
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attack…
- CVE-2023-50714HIGHCVSS 8.8EG 8.82023-12-22
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCod…
- CVE-2023-52043HIGHCVSS 8.1EG 8.12024-04-03
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication c…
- CVE-2023-52538CRITICALCVSS 9.1EG 9.12024-04-08
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-5347CRITICALCVSS 9.1EG 9.82024-01-09
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmw…
- CVE-2023-53951CRITICALCVSS 9.8EG 9.82025-12-19
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administra…
- CVE-2023-5747HIGHCVSS 8.8EG 8.82023-11-13
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing …
- CVE-2024-0567HIGHCVSS 7.5EG 7.52024-01-16
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthe…
- CVE-2024-10237HIGHCVSS 7.2EG 7.22025-02-04
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process
- CVE-2024-1149HIGHCVSS 7.8EG 7.82024-02-08
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Package…
- CVE-2024-1150HIGHCVSS 7.8EG 7.82024-02-08
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
- CVE-2024-11696MEDIUMCVSS 5.4EG 5.42024-11-26
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that …
- CVE-2024-11957CRITICALCVSS 9.3EG 9.32025-03-04
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.1…
- CVE-2024-13172HIGHCVSS 7.8EG 7.82025-01-14
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is requi…
- CVE-2024-13990CRITICALCVSS 9.3EG 9.32025-09-19
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-t…
- CVE-2024-1721MEDIUMCVSS 5.6EG 5.62024-05-21
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.
- CVE-2024-20892MEDIUMCVSS 6.5EG 6.52024-07-02
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.
- CVE-2024-21383LOWCVSS 3.3EG 3.32024-01-26
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2024-21491MEDIUMCVSS 5.9EG 5.92024-02-13
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by prov…
- CVE-2024-21669CRITICALCVSS 9.9EG 9.92024-01-11
Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data…
- CVE-2024-21917CRITICALCVSS 9.8EG 9.82024-01-31
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing betwe…
- CVE-2024-21988MEDIUMCVSS 5.3EG 5.32024-06-14
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.
- CVE-2024-22461HIGHCVSS 8.8EG 8.82024-12-13
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level acc…
- CVE-2024-2307MEDIUMCVSS 6.1EG 6.12024-03-19
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an ima…
- CVE-2024-23456HIGHCVSS 7.8EG 7.82024-08-06
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.
- CVE-2024-23460MEDIUMCVSS 6.4EG 6.42024-08-06
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
- CVE-2024-23480HIGHCVSS 7.5EG 7.52024-05-01
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
- CVE-2024-23581HIGHCVSS 7.8EG 7.82026-06-26
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
- CVE-2024-23680MEDIUMCVSS 5.3EG 5.32024-01-19
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
- CVE-2024-23960MEDIUMCVSS 4.6EG 4.62024-09-28
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically present attackers to bypass signature validation mechanism on affected installations of Alpine Halo9 devices. Authentication …
- CVE-2024-2451MEDIUMCVSS 6.4EG 6.42024-05-28
Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading.
- CVE-2024-24694MEDIUMCVSS 5.9EG 5.92024-04-09
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2024-26194HIGHCVSS 7.4EG 7.42024-04-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-26228HIGHCVSS 7.8EG 7.82024-04-09
Windows Cryptographic Services Security Feature Bypass Vulnerability
- CVE-2024-27244MEDIUMCVSS 6.7EG 6.72024-05-15
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2024-27247MEDIUMCVSS 5.5EG 5.52024-04-09
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
- CVE-2024-32911CRITICALCVSS 9.8EG 9.82024-06-13
There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-32962CRITICALCVSS 10.0EG 10.02024-05-02
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 …
- CVE-2024-34358MEDIUMCVSS 5.3EG 5.32024-05-14
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMA…
- CVE-2024-36277CRITICALCVSS 5.3EG 9.12024-06-17
Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.
- CVE-2024-36334HIGHCVSS 7.0EG 7.02026-05-15
Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arbitrary code execution.
- CVE-2024-36347MEDIUMCVSS 6.4EG 6.42025-06-27
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of co…
- CVE-2024-37532HIGHCVSS 8.8EG 8.82024-06-20
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
- CVE-2024-37568HIGHCVSS 7.5EG 7.52024-06-09
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CV…
- CVE-2024-37886MEDIUMCVSS 5.4EG 5.42024-06-14
user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to…
- CVE-2024-38069HIGHCVSS 7.0EG 7.02024-07-09
Windows Enroll Engine Security Feature Bypass Vulnerability
- CVE-2024-38807MEDIUMCVSS 6.3EG 6.32024-08-23
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →