VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 33 of 41
  • CVE-2020-8324MedApr 14, 2020
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.

  • CVE-2021-1461MedNov 18, 2024
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper…

  • CVE-2024-45607MedSep 12, 2024
    risk 0.32cvss 5.8epss 0.14

    whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid. Incorrect Access Control, anyone using the post or…

  • CVE-2020-3308MedMay 6, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due…

  • CVE-2019-11841MedMay 22, 2019
    risk 0.32cvss 5.9epss 0.02

    A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain one or more optional "Hash"…

  • CVE-2026-49834MedJul 17, 2026
    risk 0.31cvss 5.9epss 0.00

    sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a…

  • CVE-2026-48815HigJul 14, 2026
    risk 0.31cvss 7.5epss 0.00

    sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked…

  • CVE-2026-54773MedJul 8, 2026
    risk 0.31cvss 5.9epss 0.00

    CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header…

  • CVE-2026-33467MedApr 28, 2026
    risk 0.31cvss 5.9epss 0.00

    Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity…

  • CVE-2026-32883MedMar 30, 2026
    risk 0.31cvss 5.9epss 0.00

    Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response itself. This issue has been patched in…

  • CVE-2026-32294MedMar 17, 2026
    risk 0.31cvss 4.7epss 0.00

    JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.

  • CVE-2025-52648MedMar 16, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system

  • CVE-2026-23992MedJan 22, 2026
    risk 0.31cvss 5.9epss 0.00

    go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification.…

  • CVE-2024-21491MedFeb 13, 2024
    risk 0.31cvss 5.9epss 0.00

    Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches…

  • CVE-2023-42811MedSep 22, 2023
    risk 0.31cvss 4.7epss 0.00

    aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. If a program…

  • CVE-2023-28113MedMar 16, 2023
    risk 0.31cvss 5.9epss 0.01

    russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentiality. Connections between a russh client…

  • CVE-2021-34420MedNov 11, 2021
    risk 0.31cvss 4.7epss 0.00

    The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

  • CVE-2021-34715MedAug 18, 2021
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability…

  • CVE-2019-15796MedMar 26, 2020
    risk 0.31cvss 4.7epss 0.01

    Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows downloads from unsigned repositories which shouldn't be allowed and…

  • CVE-2017-18407MedAug 2, 2019
    risk 0.31cvss 4.8epss 0.00

    cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).