CWE-347
Improper Verification of Cryptographic Signature
Description
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-463 · CAPEC-475
CVEs mapped to this weakness (803)
page 13 of 41| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68757 | Hig | 0.49 | 7.5 | 0.00 | Aug 12, 2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. | ||
| CVE-2026-62918 | Hig | 0.49 | 7.5 | 0.00 | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-18089 | Hig | 0.49 | 7.5 | 0.00 | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xml in Net::SAML2::Role::VerifyXML runs "return if !$anchors && !$cacert;" as soon… | ||
| CVE-2026-32974 | Hig | 0.49 | 8.6 | 0.00 | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inject forged Feishu events and trigger… | ||
| CVE-2026-28432 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2026 | Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether… | ||
| CVE-2026-3338 | Hig | 0.49 | 7.5 | 0.01 | Mar 2, 2026 | Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should… | ||
| CVE-2026-0750 | Hig | 0.49 | 7.5 | 0.00 | Jan 28, 2026 | Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5. | ||
| CVE-2026-23967 | Hig | 0.49 | 7.5 | 0.00 | Jan 22, 2026 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library prior to version 0.3.14. An attacker can derive a new valid… | ||
| CVE-2026-20965 | Hig | 0.49 | 7.5 | 0.00 | Jan 13, 2026 | Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-64740 | Hig | 0.49 | 7.5 | 0.00 | Nov 13, 2025 | Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | ||
| CVE-2025-46774 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2025 | An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables. | ||
| CVE-2025-33074 | Hig | 0.49 | 7.5 | 0.01 | Apr 30, 2025 | Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. | ||
| CVE-2025-27773 | Hig | 0.49 | 8.6 | 0.00 | Mar 11, 2025 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the… | ||
| CVE-2025-24043 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2025 | Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. | ||
| CVE-2024-40592 | Hig | 0.49 | 7.5 | 0.00 | Nov 12, 2024 | An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package… | ||
| CVE-2024-37568 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.) | ||
| CVE-2024-23480 | Hig | 0.49 | 7.5 | 0.00 | May 1, 2024 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2. | ||
| CVE-2024-0567 | Hig | 0.49 | 7.5 | 0.01 | Jan 16, 2024 | A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to… | ||
| CVE-2023-39393 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten. | ||
| CVE-2023-39392 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten. |
- risk 0.49cvss 7.5epss 0.00
A user with access to a valid SAML response may impersonate another user under specific conditions.
- risk 0.49cvss 7.5epss 0.00
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.00
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xml in Net::SAML2::Role::VerifyXML runs "return if !$anchors && !$cacert;" as soon…
- risk 0.49cvss 8.6epss 0.00
OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inject forged Feishu events and trigger…
- risk 0.49cvss 7.5epss 0.00
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether…
- risk 0.49cvss 7.5epss 0.01
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should…
- risk 0.49cvss 7.5epss 0.00
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.
- risk 0.49cvss 7.5epss 0.00
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library prior to version 0.3.14. An attacker can derive a new valid…
- risk 0.49cvss 7.5epss 0.00
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.00
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.00
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
- risk 0.49cvss 7.5epss 0.01
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
- risk 0.49cvss 8.6epss 0.00
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the…
- risk 0.49cvss 7.5epss 0.01
Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package…
- risk 0.49cvss 7.5epss 0.00
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
- risk 0.49cvss 7.5epss 0.00
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to…
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.