VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (801)

page 2 of 41
  • CVE-2025-27670CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.00

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-20230524-0014.

  • CVE-2024-47943CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which…

  • CVE-2024-6800CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.02

    An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to…

  • CVE-2024-32911CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.00

    There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-21917CriJan 31, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.…

  • CVE-2023-44077CriJan 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

  • CVE-2023-5347CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

  • CVE-2023-28610CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.

  • CVE-2023-25718CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled…

  • CVE-2021-36226CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

  • CVE-2022-23334CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.00

    The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.

  • CVE-2020-22653CriJan 20, 2023
    risk 0.64cvss 9.8epss 0.01

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2022-31207CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This…

  • CVE-2022-31206CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native…

  • CVE-2022-31053CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any…

  • CVE-2021-43571CriNov 9, 2021
    risk 0.64cvss 9.8epss 0.01

    The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

  • CVE-2021-43569CriNov 9, 2021
    risk 0.64cvss 9.8epss 0.01

    The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

  • CVE-2021-37927CriSep 22, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

  • CVE-2021-37160CriAug 2, 2021
    risk 0.64cvss 9.8epss 0.08

    A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a…

  • CVE-2021-3406CriFeb 25, 2021
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.