CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 2 of 19
- CVE-2026-23518CRITICALCVSS 9.8EG 9.82026-01-21
Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that ar…
- CVE-2025-36418CRITICALCVSS 9.8EG 9.82026-01-20
IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to craft or modify a JSON web token in order to impersonate another user or to elevate their pri…
- CVE-2025-15444CRITICALCVSS 9.8EG 9.82026-01-06
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-692…
- CVE-2023-53951CRITICALCVSS 9.8EG 9.82025-12-19
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administra…
- CVE-2025-9485CRITICALCVSS 9.8EG 9.82025-10-04
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token process…
- CVE-2025-8454CRITICALCVSS 9.8EG 9.82025-08-01
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the up…
- CVE-2025-4658CRITICALCVSS 9.8EG 9.82025-05-13
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in Open…
- CVE-2025-3757CRITICALCVSS 9.8EG 9.82025-05-13
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
- CVE-2025-25292CRITICALCVSS 9.8EG 9.82025-03-12
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri …
- CVE-2025-25291CRITICALCVSS 9.8EG 9.82025-03-12
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri …
- CVE-2025-27670CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-20230524-0014.
- CVE-2024-47943CRITICALCVSS 9.8EG 9.82024-10-15
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an…
- CVE-2024-47832CRITICALCVSS 9.8EG 9.82024-10-09
ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying me…
- CVE-2024-6800CRITICALCVSS 9.8EG 9.82024-08-20
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an…
- CVE-2024-32911CRITICALCVSS 9.8EG 9.82024-06-13
There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2018-25099CRITICALCVSS 9.8EG 9.82024-03-18
In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.
- CVE-2024-21917CRITICALCVSS 9.8EG 9.82024-01-31
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing betwe…
- CVE-2023-44077CRITICALCVSS 9.8EG 9.82024-01-17
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
- CVE-2016-20021CRITICALCVSS 9.8EG 9.82024-01-12
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerab…
- CVE-2023-28610CRITICALCVSS 9.8EG 9.82023-03-23
The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.
- CVE-2023-25718CRITICALCVSS 9.8EG 9.82023-02-13
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end …
- CVE-2021-36226CRITICALCVSS 9.8EG 9.82023-02-06
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
- CVE-2022-23334CRITICALCVSS 9.8EG 9.82023-01-30
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
- CVE-2020-22653CRITICALCVSS 9.8EG 9.82023-01-20
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) befo…
- CVE-2022-31207CRITICALCVSS 9.8EG 9.82022-07-26
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects an…
- CVE-2022-31206CRITICALCVSS 9.8EG 9.82022-07-26
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 611…
- CVE-2022-25898CRITICALCVSS 9.8EG 9.82022-07-01
The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mist…
- CVE-2022-31053CRITICALCVSS 9.8EG 9.82022-06-13
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow…
- CVE-2021-43572CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43571CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43570CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43569CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-43568CRITICALCVSS 9.8EG 9.82021-11-09
The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- CVE-2021-37927CRITICALCVSS 9.8EG 9.82021-09-22
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- CVE-2021-38195CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.
- CVE-2021-37160CRITICALCVSS 9.8EG 9.82021-08-02
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature val…
- CVE-2021-32685CRITICALCVSS 9.8EG 9.82021-06-16
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigning…
- CVE-2021-22160CRITICALCVSS 9.8EG 9.82021-05-26
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to…
- CVE-2021-3406CRITICALCVSS 9.8EG 9.82021-02-25
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
- CVE-2020-27540CRITICALCVSS 9.8EG 9.82021-01-26
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json. fw-sign parameter and from this configuration is directly…
- CVE-2020-1026CRITICALCVSS 9.8EG 9.82020-04-15
A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bu…
- CVE-2020-6174CRITICALCVSS 9.8EG 9.82020-02-05
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
- CVE-2014-3585CRITICALCVSS 9.8EG 9.82019-11-22
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
- CVE-2019-1010161CRITICALCVSS 9.8EG 9.82019-07-25
perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network connectivity(craftin…
- CVE-2019-1010263CRITICALCVSS 9.8EG 9.82019-07-17
Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector is: networ…
- CVE-2019-13177CRITICALCVSS 9.8EG 9.82019-07-02
verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification pro…
- CVE-2019-6318CRITICALCVSS 9.8EG 9.82019-04-11
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.
- CVE-2018-5923CRITICALCVSS 9.8EG 9.82019-03-27
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.
- CVE-2018-8955CRITICALCVSS 9.8EG 9.82018-10-24
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's d…
- CVE-2017-3198CRITICALCVSS 9.8EG 9.82018-07-09
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without …
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →