CWE-347
Improper Verification of Cryptographic Signature
Description
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-463 · CAPEC-475
CVEs mapped to this weakness (884)
page 34 of 45| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41764 | Med | 0.36 | 5.5 | 0.01 | Sep 12, 2023 | Microsoft Office Spoofing Vulnerability | ||
| CVE-2023-28228 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | Windows Spoofing Vulnerability | ||
| CVE-2022-42793 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2022 | An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks. | ||
| CVE-2021-40326 | Med | 0.36 | 5.5 | 0.00 | Aug 29, 2022 | Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification. | ||
| CVE-2021-40045 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-0152 | Med | 0.36 | 5.5 | 0.00 | Nov 17, 2021 | Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2021-3421 | Med | 0.36 | 5.5 | 0.01 | May 19, 2021 | A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to… | ||
| CVE-2020-9226 | Med | 0.36 | 5.5 | 0.00 | Jul 6, 2020 | HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to load a crafted software package to the… | ||
| CVE-2018-10407 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2018 | An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by… | ||
| CVE-2016-8021 | Med | 0.36 | 5.0 | 0.04 | Mar 14, 2017 | Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file. | ||
| CVE-2026-54248 | Med | 0.35 | 6.5 | 0.00 | Sep 11, 2026 | Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy… | ||
| CVE-2026-40941 | Med | 0.35 | 6.5 | 0.00 | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31. | ||
| CVE-2026-6329 | Med | 0.35 | 6.5 | 0.00 | Jun 25, 2026 | PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parsed from the PKCS#12 structure using a… | ||
| CVE-2026-50634 | Med | 0.35 | 6.5 | 0.00 | Jun 12, 2026 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata… | ||
| CVE-2025-68113 | Med | 0.35 | 6.5 | 0.00 | Dec 16, 2025 | ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce,… | ||
| CVE-2025-55039 | Med | 0.35 | 6.5 | 0.00 | Oct 15, 2025 | This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to… | ||
| CVE-2024-11696 | Med | 0.35 | 5.4 | 0.00 | Nov 26, 2024 | The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation… | ||
| CVE-2023-46234 | Med | 0.35 | 6.5 | 0.01 | Oct 26, 2023 | browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be… | ||
| CVE-2023-35373 | Med | 0.35 | 5.3 | 0.01 | Jul 11, 2023 | Mono Authenticode Validation Spoofing Vulnerability | ||
| CVE-2023-28226 | Med | 0.35 | 5.3 | 0.01 | Apr 11, 2023 | Windows Enroll Engine Security Feature Bypass Vulnerability |
- risk 0.36cvss 5.5epss 0.01
Microsoft Office Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.00
Windows Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.00
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks.
- risk 0.36cvss 5.5epss 0.00
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
- risk 0.36cvss 5.5epss 0.00
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.01
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to…
- risk 0.36cvss 5.5epss 0.00
HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to load a crafted software package to the…
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by…
- risk 0.36cvss 5.0epss 0.04
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file.
- risk 0.35cvss 6.5epss 0.00
Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy…
- risk 0.35cvss 6.5epss 0.00
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.
- risk 0.35cvss 6.5epss 0.00
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parsed from the PKCS#12 structure using a…
- risk 0.35cvss 6.5epss 0.00
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata…
- risk 0.35cvss 6.5epss 0.00
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce,…
- risk 0.35cvss 6.5epss 0.00
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to…
- risk 0.35cvss 5.4epss 0.00
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation…
- risk 0.35cvss 6.5epss 0.01
browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be…
- risk 0.35cvss 5.3epss 0.01
Mono Authenticode Validation Spoofing Vulnerability
- risk 0.35cvss 5.3epss 0.01
Windows Enroll Engine Security Feature Bypass Vulnerability