VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 6 of 41
  • CVE-2024-47832CriOct 9, 2024
    risk 0.57cvss 9.8epss 0.00

    ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying mechanism exploits differential behavior…

  • CVE-2024-7481HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their…

  • CVE-2024-7479HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their…

  • CVE-2024-37532HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.

  • CVE-2018-25099CriMar 18, 2024
    risk 0.57cvss 9.8epss 0.00

    In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

  • CVE-2016-20021CriJan 12, 2024
    risk 0.57cvss 9.8epss 0.00

    In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.

  • CVE-2024-21669CriJan 11, 2024
    risk 0.57cvss 9.9epss 0.01

    Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of…

  • CVE-2023-44273CriSep 28, 2023
    risk 0.57cvss 9.8epss 0.01

    Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

  • CVE-2023-39211HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

  • CVE-2023-34120HigJun 13, 2023
    risk 0.57cvss 8.7epss 0.00

    Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system…

  • CVE-2022-39366CriOct 28, 2022
    risk 0.57cvss 9.9epss 0.01

    DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service…

  • CVE-2022-28752HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

  • CVE-2022-28751HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-28756HigAug 15, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2015-3298HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.

  • CVE-2022-22934HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

  • CVE-2021-43572CriNov 9, 2021
    risk 0.57cvss 9.8epss 0.01

    The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

  • CVE-2021-43570CriNov 9, 2021
    risk 0.57cvss 9.8epss 0.01

    The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

  • CVE-2021-43568CriNov 9, 2021
    risk 0.57cvss 9.8epss 0.01

    The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

  • CVE-2021-29108HigOct 1, 2021
    risk 0.57cvss 8.8epss 0.01

    There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature…