CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
805 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 1 of 17
- CVE-2002-1706HIGHCVSS 7.5EG 7.52002-12-31
Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Me…
- CVE-2002-1796HIGHCVSS 7.8EG 7.82002-12-31
ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.
- CVE-2005-2181HIGHCVSS 7.5EG 7.52005-07-11
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
- CVE-2005-2182HIGHCVSS 7.5EG 7.52005-07-11
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waitin…
- CVE-2011-3374LOWCVSS 3.7EG 3.72019-11-26
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
- CVE-2011-3965MEDIUMCVSS v2 5.0EG 5.02012-02-09
Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
- CVE-2012-2092MEDIUMCVSS 5.9EG 5.92019-12-06
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.
- CVE-2013-3900CRITICALCVSS 5.5EG 9.0⚠ KEV2013-12-11
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently suppor…
- CVE-2013-4346HIGHCVSS v2 4.3EG 7.52014-05-20
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
- CVE-2014-1498MEDIUMCVSS v2 5.0EG 5.02014-03-19
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that t…
- CVE-2014-3585CRITICALCVSS 9.8EG 9.82019-11-22
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
- CVE-2014-9934HIGHCVSS 7.8EG 7.82017-05-16
A PKCS#1 v1.5 signature verification routine in all Android releases from CAF using the Linux kernel may not check padding.
- CVE-2015-3298HIGHCVSS 8.8EG 8.82022-03-30
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
- CVE-2015-7336HIGHCVSS 7.5EG 7.52020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature chec…
- CVE-2016-1000338HIGHCVSS 7.5EG 7.52018-06-01
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate,…
- CVE-2016-1000342HIGHCVSS 7.5EG 7.52018-06-04
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validat…
- CVE-2016-11044HIGHCVSS 7.8EG 7.82020-04-07
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).
- CVE-2016-20021CRITICALCVSS 9.8EG 9.82024-01-12
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerab…
- CVE-2016-7064HIGHCVSS 7.5EG 7.52020-07-21
A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage
- CVE-2016-8021MEDIUMCVSS 5.0EG 5.02017-03-14
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input …
- CVE-2016-9604MEDIUMCVSS 4.4EG 4.42018-07-11
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to…
- CVE-2017-10669MEDIUMCVSS 6.5EG 6.52017-06-30
Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with du…
- CVE-2017-11400MEDIUMCVSS 6.8EG 6.82017-11-20
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlle…
- CVE-2017-12331MEDIUMCVSS 6.7EG 6.72017-11-30
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software …
- CVE-2017-12333MEDIUMCVSS 6.7EG 6.72017-11-30
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software …
- CVE-2017-12974HIGHCVSS 7.5EG 7.52017-08-20
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider …
- CVE-2017-13083HIGHCVSS 8.1EG 8.12017-10-18
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
- CVE-2017-15090MEDIUMCVSS 5.9EG 5.92018-01-23
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY use…
- CVE-2017-16005HIGHCVSS 7.5EG 7.52018-06-04
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if…
- CVE-2017-16852HIGHCVSS 8.1EG 8.12017-11-16
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks…
- CVE-2017-16853HIGHCVSS 8.1EG 8.12017-11-16
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security chec…
- CVE-2017-17847HIGHCVSS 7.5EG 7.52017-12-27
An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. T…
- CVE-2017-17848HIGHCVSS 7.5EG 7.52017-12-27
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In …
- CVE-2017-18122HIGHCVSS 8.1EG 8.12018-02-02
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed assertion, provided that t…
- CVE-2017-18146CRITICALCVSS 9.8EG 9.82018-04-11
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD …
- CVE-2017-18407MEDIUMCVSS 4.8EG 4.82019-08-02
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
- CVE-2017-2423CRITICALCVSS 9.8EG 9.82017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended access restrictions by leveraging …
- CVE-2017-3198CRITICALCVSS 9.8EG 9.82018-07-09
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without …
- CVE-2017-5066MEDIUMCVSS 6.5EG 6.52017-10-27
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed …
- CVE-2017-6445HIGHCVSS 8.1EG 8.12017-03-05
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root ac…
- CVE-2017-8177MEDIUMCVSS 5.3EG 5.32017-11-22
Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file. An attacker could exploit this vulnerability to hijack the APK and upload modified APK file. Successful exploit could lead to the APP i…
- CVE-2017-8190MEDIUMCVSS 6.7EG 6.72017-11-22
FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit this vulnerability to…
- CVE-2018-0114HIGHCVSS 7.5EG 7.82018-01-04
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the J…
- CVE-2018-0486MEDIUMCVSS 6.5EG 6.52018-01-13
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or…
- CVE-2018-0489MEDIUMCVSS 6.5EG 6.52018-02-27
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct…
- CVE-2018-0501MEDIUMCVSS 5.9EG 5.92018-08-21
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.
- CVE-2018-1000076CRITICALCVSS 9.8EG 9.82018-03-13
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographi…
- CVE-2018-1000539MEDIUMCVSS 5.3EG 5.32018-06-26
Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This…
- CVE-2018-10407MEDIUMCVSS 5.5EG 5.52018-06-13
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will…
- CVE-2018-10470MEDIUMCVSS 5.3EG 5.32018-06-12
Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker can maliciously cr…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →