VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (884)

page 24 of 45
  • CVE-2024-27244MedMay 15, 2024
    risk 0.44cvss 6.7epss 0.00

    Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-20568MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

  • CVE-2023-20567MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

  • CVE-2023-20236MedSep 13, 2023
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this…

  • CVE-2022-3322MedOct 28, 2022
    risk 0.44cvss 6.7epss 0.00

    Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.

  • CVE-2022-1739MedJun 24, 2022
    risk 0.44cvss 6.8epss 0.00

    The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the…

  • CVE-2021-30066MedApr 3, 2022
    risk 0.44cvss 6.8epss 0.00

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue…

  • CVE-2021-1376MedMar 24, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating…

  • CVE-2021-1375MedMar 24, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating…

  • CVE-2021-1453MedMar 24, 2021
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. The vulnerability is due to an improper check…

  • CVE-2021-1244MedFeb 4, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during…

  • CVE-2021-1136MedFeb 4, 2021
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during…

  • CVE-2020-11488MedOct 29, 2020
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware…

  • CVE-2020-3209MedJun 3, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability is due to an improper check on the area…

  • CVE-2020-3138MedFeb 19, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this…

  • CVE-2019-12662MedSep 25, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is…

  • CVE-2019-12649MedSep 25, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists because, under certain…

  • CVE-2019-5300MedJun 4, 2019
    risk 0.44cvss 6.7epss 0.00

    There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the…

  • CVE-2019-1813MedMay 15, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital…

  • CVE-2019-1812MedMay 15, 2019
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital…