CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 15 of 19
- CVE-2023-23940MEDIUMCVSS 6.4EG 6.42023-02-03
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signatu…
- CVE-2022-23540MEDIUMCVSS 6.4EG 6.42022-12-22
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected i…
- CVE-2022-47549MEDIUMCVSS 6.4EG 6.42022-12-19
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted a…
- CVE-2020-15705MEDIUMCVSS 6.4EG 6.42020-07-29
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and th…
- CVE-2018-18203MEDIUMCVSS 6.4EG 6.42018-11-28
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the vehicle's USB ports) the ability to rewrite the firmware of the head unit. This occurs beca…
- CVE-2024-50347MEDIUMCVSS 6.3EG 6.32024-10-31
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This…
- CVE-2024-38807MEDIUMCVSS 6.3EG 6.32024-08-23
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed…
- CVE-2022-39237MEDIUMCVSS 6.3EG 6.32022-10-06
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when ver…
- CVE-2026-87732MEDIUMCVSS 6.2EG 6.22026-09-09
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then c…
- CVE-2026-20699MEDIUMCVSS 6.2EG 6.22026-03-25
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to acce…
- CVE-2025-23364MEDIUMCVSS 6.2EG 6.22025-07-08
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker to bypass the check and exceute arbitrary code during …
- CVE-2025-21004MEDIUMCVSS 6.2EG 6.22025-07-08
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
- CVE-2022-31807MEDIUMCVSS 6.2EG 6.22025-05-23
A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a malicious…
- CVE-2021-43393MEDIUMCVSS 6.2EG 6.22022-03-04
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 …
- CVE-2021-43392MEDIUMCVSS 6.2EG 6.22022-03-04
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms ex…
- CVE-2026-17872MEDIUMCVSS 6.1EG 6.12026-07-30
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-2307MEDIUMCVSS 6.1EG 6.12024-03-19
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an ima…
- CVE-2022-31123MEDIUMCVSS 6.1EG 6.12022-10-13
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successful…
- CVE-2025-20248MEDIUMCVSS 6.0EG 6.02025-09-10
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit thi…
- CVE-2025-20178MEDIUMCVSS 6.0EG 6.02025-04-16
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating s…
- CVE-2021-34709MEDIUMCVSS 6.0EG 6.02021-09-09
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow…
- CVE-2021-34708MEDIUMCVSS 6.0EG 6.02021-09-09
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow…
- CVE-2020-10759MEDIUMCVSS 6.0EG 6.02020-09-15
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Se…
- CVE-2019-1729MEDIUMCVSS 6.0EG 6.02019-05-15
A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, local attacker to overwrite any file on the file system including system files. These file ov…
- CVE-2026-55174MEDIUMCVSS 5.9EG 5.92026-09-30
UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verif…
- CVE-2026-84185MEDIUMCVSS 5.9EG 5.92026-09-03
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a c…
- CVE-2026-62757MEDIUMCVSS 5.9EG 5.92026-08-11
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-66776MEDIUMCVSS 5.9EG 5.92026-08-11
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity che…
- CVE-2026-54773MEDIUMCVSS 5.9EG 5.92026-06-19
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated re…
- CVE-2026-33467MEDIUMCVSS 5.9EG 5.92026-04-28
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute …
- CVE-2026-32883MEDIUMCVSS 5.9EG 5.92026-03-30
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verifying the signature of the OCSP response …
- CVE-2025-15598MEDIUMCVSS 5.9EG 5.92026-03-03
A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verif…
- CVE-2025-68972MEDIUMCVSS 5.9EG 5.92025-12-27
In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified messag…
- CVE-2025-54549MEDIUMCVSS 5.9EG 5.92025-10-29
Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO
- CVE-2024-8036MEDIUMCVSS 5.9EG 5.92024-10-25
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the nod…
- CVE-2024-24694MEDIUMCVSS 5.9EG 5.92024-04-09
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2024-21491MEDIUMCVSS 5.9EG 5.92024-02-13
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by prov…
- CVE-2023-40012MEDIUMCVSS 5.9EG 5.92023-08-09
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.50…
- CVE-2023-3347MEDIUMCVSS 5.9EG 5.92023-07-20
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is manda…
- CVE-2023-25934MEDIUMCVSS 5.9EG 5.92023-05-04
DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the …
- CVE-2023-28113MEDIUMCVSS 5.9EG 5.92023-03-16
russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentialit…
- CVE-2023-23928MEDIUMCVSS 5.9EG 5.92023-02-01
reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could ex…
- CVE-2022-2790MEDIUMCVSS 5.9EG 5.92022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).
- CVE-2021-21405MEDIUMCVSS 5.9EG 5.92021-04-15
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized", and "compressed", meaning that BLS sig…
- CVE-2012-2092MEDIUMCVSS 5.9EG 5.92019-12-06
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.
- CVE-2019-5592MEDIUMCVSS 5.9EG 5.92019-08-23
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine version 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, 3.547 and below, when configured with S…
- CVE-2019-11841MEDIUMCVSS 5.9EG 5.92019-05-22
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message …
- CVE-2019-8338MEDIUMCVSS 5.9EG 5.92019-05-16
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed emai…
- CVE-2018-12556MEDIUMCVSS 5.9EG 5.92019-05-16
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn releas…
- CVE-2018-16253MEDIUMCVSS 5.9EG 5.92018-11-07
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metadata. Consequently, a remote attacker can forge signatures when small public exponents are being use…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →