VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 10 of 41
  • CVE-2025-57801CriAug 22, 2025
    risk 0.52cvss 9.1epss 0.00

    gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that 0 ≤ S < order, leading to a signature malleability vulnerability. Because gnark’s native EdDSA…

  • CVE-2025-2764HigApr 23, 2025
    risk 0.52cvss 8.0epss 0.00

    CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Although authentication is…

  • CVE-2024-54150CriDec 19, 2024
    risk 0.52cvss 9.1epss 0.00

    cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing attackers to exploit the lack of distinction between signing methods. If the system doesn't differentiate between an HMAC signed…

  • CVE-2024-48949CriOct 10, 2024
    risk 0.52cvss 9.1epss 0.01

    The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.

  • CVE-2024-42461CriAug 2, 2024
    risk 0.52cvss 9.1epss 0.01

    In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

  • CVE-2023-34205CriMay 30, 2023
    risk 0.52cvss 9.1epss 0.00

    In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).

  • CVE-2021-29451CriApr 16, 2021
    risk 0.52cvss 9.1epss 0.01

    Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens. This allows forging a valid JWT. The issue will be patched in the upcoming 5.2.1 release.

  • CVE-2019-14859CriJan 2, 2020
    risk 0.52cvss 9.1epss 0.02

    A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could…

  • CVE-2025-13662HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.

  • CVE-2025-34324HigNov 18, 2025
    risk 0.51cvss 7.8epss 0.00

    GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs and SHA-256 hashes but is not digitally signed, so its authenticity relies solely on the underlying TLS channel. In affected…

  • CVE-2024-13172HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2024-47476HigDec 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2024-7788HigSep 17, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.

  • CVE-2024-23456HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

  • CVE-2023-50228HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to…

  • CVE-2024-26228HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Windows Cryptographic Services Security Feature Bypass Vulnerability

  • CVE-2024-1150HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.

  • CVE-2024-1149HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent:…

  • CVE-2023-43611HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerability is due to an incomplete fix for CVE-2023-38418.  Note: Software versions which have reached End of Technical Support (EoTS)…

  • CVE-2023-40727HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism. This could allow an attacker to tamper the application code.