VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (801)

page 11 of 41
  • CVE-2023-41744HigAug 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) before build 30600, Acronis Cyber Protect 15 (macOS) before build 35979.

  • CVE-2023-38418HigAug 2, 2023
    risk 0.51cvss 7.8epss 0.00

    The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-4418HigMay 18, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208.

  • CVE-2022-20929HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature…

  • CVE-2023-20940HigFeb 28, 2023
    risk 0.51cvss 7.8epss 0.00

    In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-34459HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload…

  • CVE-2021-26391HigNov 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.

  • CVE-2022-24115HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287

  • CVE-2020-16156HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.01

    CPAN 2.28 allows Signature Verification Bypass.

  • CVE-2020-16154HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.01

    The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

  • CVE-2021-36277HigAug 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system.

  • CVE-2020-23967HigMar 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.

  • CVE-2021-1366HigFeb 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the…

  • CVE-2020-28045HigNov 2, 2020
    risk 0.51cvss 7.8epss 0.00

    An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of Sale application developer and distributor. The signature is a 2048-byte RSA…

  • CVE-2019-10562HigSep 8, 2020
    risk 0.51cvss 7.8epss 0.00

    u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer…

  • CVE-2020-10608HigJul 24, 2020
    risk 0.51cvss 7.8epss 0.00

    In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in…

  • CVE-2019-10575HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM850

  • CVE-2016-11044HigApr 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

  • CVE-2019-0071HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.00

    Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be executed. Due to a flaw in specific versions of Junos OS, affecting specific EX Series platforms, the Veriexec subsystem will fail to initialize, in essence…

  • CVE-2019-5299HigAug 13, 2019
    risk 0.51cvss 7.8epss 0.01

    Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can induce users to install malicious applications. Due to a defect in the signature verification logic, the malicious applications can…