VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 32 of 41
  • CVE-2026-62757MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-67903MedMay 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.

  • CVE-2026-6966MedApr 24, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept…

  • CVE-2026-2746MedMar 4, 2026
    risk 0.34cvss 5.3epss 0.00

    SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect forged emails.

  • CVE-2026-27445MedMar 4, 2026
    risk 0.34cvss 5.3epss 0.00

    SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signature spoofing.

  • CVE-2025-59803MedDec 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the…

  • CVE-2025-55229MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-49394MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

  • CVE-2024-50347MedOct 31, 2024
    risk 0.34cvss epss 0.00

    Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in scenarios such as…

  • CVE-2024-41258MedJul 31, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.

  • CVE-2024-41254MedJul 31, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.

  • CVE-2024-36277MedJun 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.

  • CVE-2024-21988MedJun 14, 2024
    risk 0.34cvss 5.3epss 0.00

    StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.

  • CVE-2024-23680MedJan 19, 2024
    risk 0.34cvss 5.3epss 0.00

    AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

  • CVE-2023-28818MedMar 24, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable…

  • CVE-2022-39237MedOct 6, 2022
    risk 0.34cvss 6.3epss 0.01

    syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is…

  • CVE-2021-39909MedNov 5, 2021
    risk 0.34cvss 5.3epss 0.01

    Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge…

  • CVE-2017-8177MedNov 22, 2017
    risk 0.34cvss 5.3epss 0.00

    Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file. An attacker could exploit this vulnerability to hijack the APK and upload modified APK file. Successful exploit could lead to the APP is hijacking.

  • CVE-2025-33069MedJun 10, 2025
    risk 0.33cvss 5.1epss 0.00

    Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2022-31123MedOct 13, 2022
    risk 0.33cvss 6.1epss 0.00

    Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though…