VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 14 of 41
  • CVE-2023-24025HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.

  • CVE-2020-22659HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2022-3347HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.00

    DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

  • CVE-2020-25166HigApr 14, 2022
    risk 0.49cvss 7.6epss 0.00

    An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can…

  • CVE-2021-25636HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice…

  • CVE-2022-21134HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-41832HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.01

    It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.

  • CVE-2021-41830HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.01

    It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory.

  • CVE-2021-1849HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.

  • CVE-2021-34433HigAug 20, 2021
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's…

  • CVE-2021-24020HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.01

    A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allows bypass of signature verification.

  • CVE-2021-29500HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. This allows to forgery of valid JWTs.

  • CVE-2021-33054HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)

  • CVE-2021-28091HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

  • CVE-2021-3445HigMay 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of…

  • CVE-2020-36285HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret…

  • CVE-2020-36284HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key…

  • CVE-2020-23533HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a…

  • CVE-2020-28086HigDec 9, 2020
    risk 0.49cvss 7.5epss 0.01

    pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the central Git server or one of the other…

  • CVE-2020-26540HigOct 2, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.