CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 14 of 19
- CVE-2026-86109MEDIUMCVSS 6.6EG 6.62026-09-16
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficie…
- CVE-2026-52486MEDIUMCVSS 6.6EG 6.62026-09-08
An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module
- CVE-2022-31156MEDIUMCVSS 6.6EG 6.62022-07-14
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through …
- CVE-2019-1736MEDIUMCVSS 6.6EG 6.62020-09-23
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software ima…
- CVE-2026-54248MEDIUMCVSS 6.5EG 6.52026-09-11
Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided de…
- CVE-2026-40941MEDIUMCVSS 6.5EG 6.52026-06-25
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.
- CVE-2026-6329MEDIUMCVSS 6.5EG 6.52026-06-25
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parse…
- CVE-2026-42743MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
- CVE-2026-50634MEDIUMCVSS 6.5EG 6.52026-06-12
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-T…
- CVE-2026-39413MEDIUMCVSS 6.5EG 6.52026-04-08
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since t…
- CVE-2026-22818MEDIUMCVSS 6.5EG 6.52026-01-13
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signatur…
- CVE-2026-22817MEDIUMCVSS 6.5EG 6.52026-01-13
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verificatio…
- CVE-2025-68113MEDIUMCVSS 6.5EG 6.52025-12-16
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind c…
- CVE-2025-55311MEDIUMCVSS 6.5EG 6.52025-12-11
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript int…
- CVE-2025-64186MEDIUMCVSS 6.5EG 6.52025-11-12
Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 that may allow incomplete documents to pass validation. This…
- CVE-2025-55039MEDIUMCVSS 6.5EG 6.52025-10-15
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.cry…
- CVE-2024-6580MEDIUMCVSS 6.5EG 6.52024-07-08
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component…
- CVE-2024-20892MEDIUMCVSS 6.5EG 6.52024-07-02
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.
- CVE-2023-49646MEDIUMCVSS 6.5EG 6.52023-12-13
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
- CVE-2023-42806MEDIUMCVSS 6.5EG 6.52023-09-21
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of this head) to use a snapshot from an old head instance with the…
- CVE-2023-20266MEDIUMCVSS 6.5EG 6.52023-08-30
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, rem…
- CVE-2021-43171MEDIUMCVSS 6.5EG 6.52023-08-22
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the…
- CVE-2023-33768MEDIUMCVSS 6.5EG 6.52023-07-13
Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file.
- CVE-2022-42010MEDIUMCVSS 6.5EG 6.52022-10-10
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain …
- CVE-2022-26510MEDIUMCVSS 6.5EG 6.52022-05-12
A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger …
- CVE-2021-20156MEDIUMCVSS 6.5EG 6.52021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not ap…
- CVE-2021-32738MEDIUMCVSS 6.5EG 6.52021-07-02
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the cha…
- CVE-2021-23993MEDIUMCVSS 6.5EG 6.52021-06-24
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the cra…
- CVE-2021-21474MEDIUMCVSS 6.5EG 6.52021-02-09
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that t…
- CVE-2021-21239MEDIUMCVSS 6.5EG 6.52021-01-21
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to …
- CVE-2021-21238MEDIUMCVSS 6.5EG 6.52021-01-21
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. …
- CVE-2020-29438MEDIUMCVSS 6.5EG 6.52020-11-30
Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construct firmware that retrieves an unlock code from a secure enclave chip.
- CVE-2019-8901MEDIUMCVSS 6.5EG 6.52020-10-27
This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH traffic from the �…
- CVE-2020-15091MEDIUMCVSS 6.5EG 6.52020-07-02
TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chain…
- CVE-2020-14199MEDIUMCVSS 6.5EG 6.52020-06-16
BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this aff…
- CVE-2020-12042MEDIUMCVSS 6.5EG 6.52020-05-14
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system acces…
- CVE-2019-3738MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predic…
- CVE-2019-9149MEDIUMCVSS 6.5EG 6.52019-07-09
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the pr…
- CVE-2018-15587MEDIUMCVSS 6.5EG 6.52019-02-11
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
- CVE-2018-15586MEDIUMCVSS 6.5EG 6.52019-02-11
Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.
- CVE-2018-0489MEDIUMCVSS 6.5EG 6.52018-02-27
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct…
- CVE-2018-0486MEDIUMCVSS 6.5EG 6.52018-01-13
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or…
- CVE-2017-5066MEDIUMCVSS 6.5EG 6.52017-10-27
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed …
- CVE-2017-10669MEDIUMCVSS 6.5EG 6.52017-06-30
Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with du…
- CVE-2026-94212MEDIUMCVSS 6.4EG 6.42026-10-01
Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects A…
- CVE-2026-50720MEDIUMCVSS 6.4EG 6.42026-08-19
The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attacker…
- CVE-2026-13305MEDIUMCVSS 6.4EG 6.42026-07-29
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installat…
- CVE-2024-36347MEDIUMCVSS 6.4EG 6.42025-06-27
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of co…
- CVE-2024-23460MEDIUMCVSS 6.4EG 6.42024-08-06
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
- CVE-2024-2451MEDIUMCVSS 6.4EG 6.42024-05-28
Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading.
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →