CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 10 of 19
- CVE-2021-41830HIGHCVSS 7.5EG 7.52021-10-11
It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-2563…
- CVE-2021-1849HIGHCVSS 7.5EG 7.52021-09-08
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.
- CVE-2021-34433HIGHCVSS 7.5EG 7.52021-08-20
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not i…
- CVE-2021-29500HIGHCVSS 7.5EG 7.52021-06-04
bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. Th…
- CVE-2021-33054HIGHCVSS 7.5EG 7.52021-06-04
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (On…
- CVE-2021-28091HIGHCVSS 7.5EG 7.52021-06-04
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
- CVE-2021-3445HIGHCVSS 7.5EG 7.52021-05-19
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system …
- CVE-2021-29455HIGHCVSS 7.5EG 7.52021-04-19
Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform before master deployment as of 2021-04-16 did not properly verify the sig…
- CVE-2020-36285HIGHCVSS 7.5EG 7.52021-04-06
Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (M…
- CVE-2020-36284HIGHCVSS 7.5EG 7.52021-04-06
Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) …
- CVE-2020-23533HIGHCVSS 7.5EG 7.52021-04-06
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (…
- CVE-2021-30130HIGHCVSS 7.5EG 7.52021-04-06
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
- CVE-2020-11093HIGHCVSS 7.5EG 7.52020-12-24
Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12.4, there is lack of signature verification on a specific transaction which enables an att…
- CVE-2020-28086HIGHCVSS 7.5EG 7.52020-12-09
pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the c…
- CVE-2020-26540HIGHCVSS 7.5EG 7.52020-10-02
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
- CVE-2020-14515HIGHCVSS 7.5EG 7.52020-09-16
CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forgi…
- CVE-2020-13101HIGHCVSS 7.5EG 7.52020-08-24
In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signature, when the InlineXML option is used…
- CVE-2020-15827HIGHCVSS 7.5EG 7.52020-08-08
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
- CVE-2020-15957HIGHCVSS 7.5EG 7.52020-07-30
An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by prov…
- CVE-2016-7064HIGHCVSS 7.5EG 7.52020-07-21
A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage
- CVE-2020-13845HIGHCVSS 7.5EG 7.52020-07-14
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descripto…
- CVE-2020-15302HIGHCVSS 7.5EG 7.52020-06-25
In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeove…
- CVE-2020-14966HIGHCVSS 7.5EG 7.52020-06-22
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The mod…
- CVE-2019-20837HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-standard signatures.
- CVE-2019-20834HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit PhantomPDF before 8.3.10. It allows signature validation bypass via a modified file or a file with non-standard signatures.
- CVE-2020-13810HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.
- CVE-2020-13803HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a file with non-standard signatures.
- CVE-2020-12607HIGHCVSS 7.5EG 7.52020-06-02
An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1, the signature verification fails even …
- CVE-2020-13415HIGHCVSS 7.5EG 7.52020-05-22
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized t…
- CVE-2020-12244HIGHCVSS 7.5EG 7.52020-05-19
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validat…
- CVE-2019-17561HIGHCVSS 7.5EG 7.52020-03-30
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerabilit…
- CVE-2015-7336HIGHCVSS 7.5EG 7.52020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature chec…
- CVE-2020-9283HIGHCVSS 7.5EG 7.52020-02-20
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack…
- CVE-2020-7906HIGHCVSS 7.5EG 7.52020-01-30
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
- CVE-2020-5390HIGHCVSS 7.5EG 7.52020-01-13
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is si…
- CVE-2019-19962HIGHCVSS 7.5EG 7.52019-12-25
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
- CVE-2019-16753HIGHCVSS 7.5EG 7.52019-12-04
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak si…
- CVE-2019-16992HIGHCVSS 7.5EG 7.52019-09-30
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), wh…
- CVE-2019-11755HIGHCVSS 7.5EG 7.52019-09-27
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might …
- CVE-2019-15545HIGHCVSS 7.5EG 7.52019-08-26
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.
- CVE-2019-9154HIGHCVSS 7.5EG 7.52019-08-22
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
- CVE-2019-9153HIGHCVSS 7.5EG 7.52019-08-22
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.
- CVE-2019-1010279HIGHCVSS 7.5EG 7.52019-07-18
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequence of network packe…
- CVE-2019-12269HIGHCVSS 7.5EG 7.52019-05-21
Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
- CVE-2018-7340HIGHCVSS 7.5EG 7.52019-04-17
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signatur…
- CVE-2018-16152HIGHCVSS 7.5EG 7.52018-09-26
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 s…
- CVE-2018-16151HIGHCVSS 7.5EG 7.52018-09-26
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature…
- CVE-2018-15836HIGHCVSS 7.5EG 7.52018-09-26
In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge sig…
- CVE-2018-5387HIGHCVSS 7.5EG 7.52018-07-24
Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the atta…
- CVE-2018-12019HIGHCVSS 7.5EG 7.52018-06-13
The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signa…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →