VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (884)

page 32 of 45
  • CVE-2020-10759MedSep 15, 2020
    risk 0.39cvss 6.0epss 0.00

    A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented…

  • CVE-2012-2092MedDec 6, 2019
    risk 0.39cvss 5.9epss 0.04

    A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.

  • CVE-2019-1729MedMay 15, 2019
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, local attacker to overwrite any file on the file system including system files. These file overwrites by the attacker are…

  • CVE-2026-78223MedSep 17, 2026
    risk 0.38cvss —epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.TokenResource.RevokeTokenChange.change/3…

  • CVE-2026-84185MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to…

  • CVE-2026-72861MedAug 20, 2026
    risk 0.38cvss 5.8epss 0.00

    The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await…

  • CVE-2026-74244MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful…

  • CVE-2026-66776MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session…

  • CVE-2026-9793MedMay 28, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit…

  • CVE-2025-68972MedDec 27, 2025
    risk 0.38cvss 5.9epss 0.00

    In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor"…

  • CVE-2025-54549MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

  • CVE-2024-8036MedOct 25, 2024
    risk 0.38cvss 5.9epss 0.00

    ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or…

  • CVE-2024-24694MedApr 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-31580MedOct 25, 2023
    risk 0.38cvss 5.9epss 0.01

    light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.

  • CVE-2023-3347MedJul 20, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to…

  • CVE-2023-25934MedMay 4, 2023
    risk 0.38cvss 5.9epss 0.00

    DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request.

  • CVE-2022-2790MedAug 19, 2022
    risk 0.38cvss 5.9epss 0.00

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).

  • CVE-2021-26100MedJul 9, 2021
    risk 0.38cvss 5.9epss 0.00

    A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of the plaintexts possible.

  • CVE-2019-5592MedAug 23, 2019
    risk 0.38cvss 5.9epss 0.01

    Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, when configured with SSL Deep Inspection policies and with the…

  • CVE-2019-8338MedMay 16, 2019
    risk 0.38cvss 5.9epss 0.02

    The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed email with an invalid signature. Also, it…