VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (801)

page 21 of 41
  • CVE-2020-9047MedJun 26, 2020
    risk 0.45cvss 6.8epss 0.08

    A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative…

  • CVE-2026-16742MedAug 10, 2026
    risk 0.44cvss 6.7epss 0.00

    systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

  • CVE-2026-35205HigApr 9, 2026
    risk 0.44cvss 7.8epss 0.00

    Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

  • CVE-2025-32060MedFeb 15, 2026
    risk 0.44cvss 6.7epss 0.00

    The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the…

  • CVE-2025-4371MedAug 18, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection.

  • CVE-2025-20181MedMay 7, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot…

  • CVE-2025-2763MedApr 23, 2025
    risk 0.44cvss 6.8epss 0.00

    CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to…

  • CVE-2025-20143MedMar 12, 2025
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have…

  • CVE-2024-5912MedJul 10, 2024
    risk 0.44cvss epss 0.00

    An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being…

  • CVE-2024-27244MedMay 15, 2024
    risk 0.44cvss 6.7epss 0.00

    Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-20568MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

  • CVE-2023-20567MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

  • CVE-2023-20236MedSep 13, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this…

  • CVE-2022-3322MedOct 28, 2022
    risk 0.44cvss 6.7epss 0.00

    Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.

  • CVE-2022-1739MedJun 24, 2022
    risk 0.44cvss 6.8epss 0.00

    The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the…

  • CVE-2021-30066MedApr 3, 2022
    risk 0.44cvss 6.8epss 0.00

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue…

  • CVE-2021-1376MedMar 24, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating…

  • CVE-2021-1375MedMar 24, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating…

  • CVE-2021-1453MedMar 24, 2021
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. The vulnerability is due to an improper check…

  • CVE-2021-1244MedFeb 4, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during…