VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (801)

page 7 of 41
  • CVE-2021-32685CriJun 16, 2021
    risk 0.57cvss 9.8epss 0.01

    tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any…

  • CVE-2021-3196HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity management (authenticating via SAML through a third-party identity provider), an attacker can inject additional data into a…

  • CVE-2020-13593HigAug 31, 2020
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipped if the Link Layer encryption setup is performed earlier.…

  • CVE-2020-5407HigMay 13, 2020
    risk 0.57cvss 8.8epss 0.01

    Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML…

  • CVE-2020-6174CriFeb 5, 2020
    risk 0.57cvss 9.8epss 0.01

    TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

  • CVE-2019-18835CriNov 8, 2019
    risk 0.57cvss 9.8epss 0.01

    Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

  • CVE-2019-13177CriJul 2, 2019
    risk 0.57cvss 9.8epss 0.02

    verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code…

  • CVE-2018-1000076CriMar 13, 2018
    risk 0.57cvss 9.8epss 0.03

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb…

  • CVE-2026-10754HigAug 10, 2026
    risk 0.56cvss epss 0.01

    Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

  • CVE-2026-13722HigJul 3, 2026
    risk 0.56cvss epss 0.00

    WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.

  • CVE-2026-58426CriJul 3, 2026
    risk 0.55cvss 9.6epss 0.00

    Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

  • CVE-2025-12007HigJan 16, 2026
    risk 0.55cvss 8.4epss 0.00

    There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.

  • CVE-2025-64456HigNov 10, 2025
    risk 0.55cvss 8.4epss 0.00

    In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

  • CVE-2025-59934CriSep 26, 2025
    risk 0.55cvss 9.4epss 0.08

    Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email…

  • CVE-2024-54126HigDec 5, 2024
    risk 0.55cvss epss 0.00

    This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading…

  • CVE-2018-0114HigJan 4, 2018
    risk 0.55cvss 7.5epss 0.43

    A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for…

  • CVE-2025-29775CriMar 14, 2025
    risk 0.54cvss epss 0.09

    xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication or authorization mechanisms in systems that rely on xml-crypto for verifying signed…

  • CVE-2025-29774CriMar 14, 2025
    risk 0.54cvss epss 0.09

    xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication or authorization mechanisms in systems that rely on xml-crypto for verifying signed…

  • CVE-2020-26290CriDec 28, 2020
    risk 0.54cvss 9.3epss 0.01

    Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due to issues with XML encoding in the…

  • CVE-2026-15556HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.