VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 15 of 41
  • CVE-2020-14515HigSep 16, 2020
    risk 0.49cvss 7.5epss 0.01

    CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a…

  • CVE-2020-13101HigAug 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signature, when the InlineXML option is used. This defeats the expectation of…

  • CVE-2020-10126HigAug 21, 2020
    risk 0.49cvss 7.6epss 0.00

    NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer and execute arbitrary code with SYSTEM privileges because…

  • CVE-2020-15827HigAug 8, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.

  • CVE-2020-15957HigJul 30, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by providing a JWT token with alg=none.

  • CVE-2020-13845HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a…

  • CVE-2020-15093HigJul 9, 2020
    risk 0.49cvss 8.6epss 0.01

    The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is…

  • CVE-2020-15302HigJun 25, 2020
    risk 0.49cvss 7.5epss 0.01

    In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeover.

  • CVE-2019-20837HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-standard signatures.

  • CVE-2019-20834HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PhantomPDF before 8.3.10. It allows signature validation bypass via a modified file or a file with non-standard signatures.

  • CVE-2020-13810HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.

  • CVE-2020-13803HigJun 4, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a file with non-standard signatures.

  • CVE-2020-13415HigMay 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature…

  • CVE-2020-12244HigMay 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.

  • CVE-2019-17561HigMar 30, 2020
    risk 0.49cvss 7.5epss 0.02

    The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

  • CVE-2015-7336HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.

  • CVE-2020-7906HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

  • CVE-2019-16753HigDec 4, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow…

  • CVE-2019-16992HigSep 30, 2019
    risk 0.49cvss 7.5epss 0.01

    The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's…

  • CVE-2019-11755HigSep 27, 2019
    risk 0.49cvss 7.5epss 0.01

    A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from…