CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 13 of 19
- CVE-2025-34500HIGHCVSS 7.0EG 7.02025-10-24
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with…
- CVE-2024-38069HIGHCVSS 7.0EG 7.02024-07-09
Windows Enroll Engine Security Feature Bypass Vulnerability
- CVE-2018-3968HIGHCVSS 7.0EG 7.02019-03-21
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verifie…
- CVE-2026-78223MEDIUMCVSS 6.9EG 6.92026-09-17
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.…
- CVE-2026-44720MEDIUMCVSS 6.9EG 6.92026-05-27
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditi…
- CVE-2026-95503MEDIUMCVSS 6.8EG 6.82026-09-22
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Dist…
- CVE-2026-50719MEDIUMCVSS 6.8EG 6.82026-08-19
The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table pars…
- CVE-2026-10723MEDIUMCVSS 6.8EG 6.82026-07-22
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23…
- CVE-2026-34068MEDIUMCVSS 6.8EG 6.82026-04-22
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_voting_key=Some(...)` while omitting `new_pro…
- CVE-2025-4371MEDIUMCVSS 6.8EG 6.82025-08-18
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection.
- CVE-2025-20181MEDIUMCVSS 6.8EG 6.82025-05-07
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the devi…
- CVE-2025-2763MEDIUMCVSS 6.8EG 6.82025-04-23
CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA device…
- CVE-2024-5912MEDIUMCVSS 6.8EG 6.82024-07-10
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to exe…
- CVE-2021-30066MEDIUMCVSS 6.8EG 6.82022-04-03
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick)…
- CVE-2021-1453MEDIUMCVSS 6.8EG 6.82021-03-24
A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. The vu…
- CVE-2020-26244MEDIUMCVSS 6.8EG 6.82020-12-02
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algori…
- CVE-2020-9047MEDIUMCVSS 6.8EG 6.82020-06-26
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior…
- CVE-2020-3209MEDIUMCVSS 6.8EG 6.82020-06-03
A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability …
- CVE-2018-5383MEDIUMCVSS 6.8EG 6.82018-08-07
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used…
- CVE-2017-11400MEDIUMCVSS 6.8EG 6.82017-11-20
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlle…
- CVE-2022-20944MEDIUMCVSS 6.1EG 6.82022-10-10
A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerab…
- CVE-2026-16742MEDIUMCVSS 6.7EG 6.72026-08-10
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
- CVE-2025-32060MEDIUMCVSS 6.7EG 6.72026-02-15
The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the ke…
- CVE-2025-20143MEDIUMCVSS 6.7EG 6.72025-03-12
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vuln…
- CVE-2024-27244MEDIUMCVSS 6.7EG 6.72024-05-15
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2023-41337MEDIUMCVSS 6.7EG 6.72023-12-12
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple addresses or ports with each of them using different backend servers managed by multiple ent…
- CVE-2023-20568MEDIUMCVSS 6.7EG 6.72023-11-14
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code executi…
- CVE-2023-20567MEDIUMCVSS 6.7EG 6.72023-11-14
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code ex…
- CVE-2023-20236MEDIUMCVSS 6.7EG 6.72023-09-13
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification.…
- CVE-2022-3322MEDIUMCVSS 6.7EG 6.72022-10-28
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using…
- CVE-2021-1376MEDIUMCVSS 6.7EG 6.72021-03-24
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbit…
- CVE-2021-1375MEDIUMCVSS 6.7EG 6.72021-03-24
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbit…
- CVE-2021-1244MEDIUMCVSS 6.7EG 6.72021-02-04
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local …
- CVE-2021-1136MEDIUMCVSS 6.7EG 6.72021-02-04
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local …
- CVE-2020-11488MEDIUMCVSS 6.7EG 6.72020-10-29
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public k…
- CVE-2020-3138MEDIUMCVSS 6.7EG 6.72020-02-19
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature va…
- CVE-2019-12662MEDIUMCVSS 6.7EG 6.72019-09-25
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on …
- CVE-2019-12649MEDIUMCVSS 6.7EG 6.72019-09-25
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability ex…
- CVE-2019-5300MEDIUMCVSS 6.7EG 6.72019-06-04
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly ve…
- CVE-2019-1813MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerab…
- CVE-2019-1812MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerab…
- CVE-2019-1811MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerab…
- CVE-2019-1810MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a mal…
- CVE-2019-1809MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerab…
- CVE-2019-1728MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. Th…
- CVE-2019-1615MEDIUMCVSS 6.7EG 6.72019-03-11
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerab…
- CVE-2018-15374MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software …
- CVE-2017-12333MEDIUMCVSS 6.7EG 6.72017-11-30
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software …
- CVE-2017-12331MEDIUMCVSS 6.7EG 6.72017-11-30
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software …
- CVE-2017-8190MEDIUMCVSS 6.7EG 6.72017-11-22
FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit this vulnerability to…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →