VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 4 of 41
  • CVE-2024-11957CriMar 4, 2025
    risk 0.60cvss epss 0.00

    Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not…

  • CVE-2023-49079CriNov 29, 2023
    risk 0.60cvss 9.3epss 0.00

    Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.

  • CVE-2026-7557CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This…

  • CVE-2026-41005CriJun 11, 2026
    risk 0.59cvss 9.0epss 0.00

    Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when…

  • CVE-2026-0234CriApr 13, 2026
    risk 0.59cvss 9.1epss 0.00

    An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

  • CVE-2026-3564CriMar 17, 2026
    risk 0.59cvss 9.0epss 0.00

    A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not…

  • CVE-2025-43023CriJul 28, 2025
    risk 0.59cvss 9.1epss 0.00

    A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).

  • CVE-2024-47073CriNov 7, 2024
    risk 0.59cvss 9.1epss 0.01

    DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any…

  • CVE-2024-45409CriSep 10, 2024
    risk 0.59cvss 10.0epss 0.11

    The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus…

  • CVE-2023-52538CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2020-35169CriJul 11, 2022
    risk 0.59cvss 9.1epss 0.01

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.

  • CVE-2021-46743CriMar 29, 2022
    risk 0.59cvss 9.1epss 0.01

    In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a…

  • CVE-2022-23610CriMar 16, 2022
    risk 0.59cvss 9.1epss 0.01

    wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possible to craft DSA Signatures to bypass SAML SSO and impersonate any Wire user with SAML credentials. In teams with SAML, but without…

  • CVE-2021-20487CriMay 26, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.

  • CVE-2021-30246CriApr 7, 2021
    risk 0.59cvss 9.1epss 0.01

    In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.

  • CVE-2021-3033CriFeb 10, 2021
    risk 0.59cvss 9.1epss 0.01

    An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud Compute console as…

  • CVE-2020-12676CriOct 2, 2020
    risk 0.59cvss 9.1epss 0.03

    FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".

  • CVE-2020-9753CriMay 20, 2020
    risk 0.59cvss 9.1epss 0.01

    Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

  • CVE-2019-20597CriMar 24, 2020
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modify user-input logs. The Samsung ID is SVE-2019-14170 (June 2019).

  • CVE-2026-54782CriJul 8, 2026
    risk 0.58cvss 10.0epss 0.00

    CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used…