VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 28 of 41
  • CVE-2026-58262HigAug 7, 2026
    risk 0.39cvss epss 0.00

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not correspond to any validator and are ignored…

  • CVE-2026-42462HigJun 10, 2026
    risk 0.39cvss 7.0epss 0.00

    Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it…

  • CVE-2025-20248MedSep 10, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have…

  • CVE-2025-20178MedApr 16, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vulnerability is due to…

  • CVE-2025-25305HigFeb 18, 2025
    risk 0.39cvss 7.0epss 0.00

    Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the…

  • CVE-2022-35930HigAug 4, 2022
    risk 0.39cvss 7.1epss 0.01

    PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a false positive, resulting in an admission when it should not be admitted when there is at least one attestation with a valid…

  • CVE-2022-35929HigAug 4, 2022
    risk 0.39cvss 7.1epss 0.01

    cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used with the `--type` flag will report a false positive verification when there is at least one…

  • CVE-2021-34709MedSep 9, 2021
    risk 0.39cvss 6.0epss 0.00

    Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to…

  • CVE-2021-34708MedSep 9, 2021
    risk 0.39cvss 6.0epss 0.00

    Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to…

  • CVE-2020-14365HigSep 23, 2020
    risk 0.39cvss 7.1epss 0.00

    A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default…

  • CVE-2020-10759MedSep 15, 2020
    risk 0.39cvss 6.0epss 0.00

    A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented…

  • CVE-2012-2092MedDec 6, 2019
    risk 0.39cvss 5.9epss 0.04

    A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.

  • CVE-2019-1729MedMay 15, 2019
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, local attacker to overwrite any file on the file system including system files. These file overwrites by the attacker are…

  • CVE-2026-66776MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session…

  • CVE-2026-52767higJul 9, 2026
    risk 0.38cvss epss

    ## Summary `HttpSignatureService::verifySignature()` checks the result of PHP's `openssl_verify()` with a **loose boolean negation** - `if (!openssl_verify(...)) { throw ... }`. PHP's `openssl_verify` has four possible return values: | return | meaning …

  • CVE-2026-9793MedMay 28, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit…

  • CVE-2025-68972MedDec 27, 2025
    risk 0.38cvss 5.9epss 0.00

    In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor"…

  • CVE-2025-54549MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

  • CVE-2024-8036MedOct 25, 2024
    risk 0.38cvss 5.9epss 0.00

    ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or…

  • CVE-2024-24694MedApr 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.