CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
805 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 4 of 17
- CVE-2020-13810HIGHCVSS 7.5EG 7.52020-06-04
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.
- CVE-2020-13845HIGHCVSS 7.5EG 7.52020-07-14
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descripto…
- CVE-2020-13895HIGHCVSS 8.8EG 8.82020-06-07
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve secp256r1 (prime256v1). This could conc…
- CVE-2020-14199MEDIUMCVSS 6.5EG 6.52020-06-16
BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this aff…
- CVE-2020-14365HIGHCVSS 7.1EG 7.12020-09-23
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check…
- CVE-2020-14515HIGHCVSS 7.5EG 7.52020-09-16
CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forgi…
- CVE-2020-1464CRITICALCVSS 7.8EG 9.0⚠ KEV2020-08-17
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attack…
- CVE-2020-14966HIGHCVSS 7.5EG 7.52020-06-22
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The mod…
- CVE-2020-15091MEDIUMCVSS 6.5EG 6.52020-07-02
TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chain…
- CVE-2020-15093HIGHCVSS 8.6EG 8.62020-07-09
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of …
- CVE-2020-15216MEDIUMCVSS 5.3EG 5.32020-09-29
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available…
- CVE-2020-15240HIGHCVSS 7.4EG 7.42020-10-21
omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to bypass authentication…
- CVE-2020-15302HIGHCVSS 7.5EG 7.52020-06-25
In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeove…
- CVE-2020-15705MEDIUMCVSS 6.4EG 6.42020-07-29
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and th…
- CVE-2020-15827HIGHCVSS 7.5EG 7.52020-08-08
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
- CVE-2020-15957HIGHCVSS 7.5EG 7.52020-07-30
An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by prov…
- CVE-2020-16154HIGHCVSS 7.8EG 7.82021-12-13
The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.
- CVE-2020-16156HIGHCVSS 7.8EG 7.82021-12-13
CPAN 2.28 allows Signature Verification Bypass.
- CVE-2020-16922MEDIUMCVSS 5.3EG 5.32020-10-16
<p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario,…
- CVE-2020-2021CRITICALCVSS 10.0EG 10.0⚠ KEV2020-06-29
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthen…
- CVE-2020-2146HIGHCVSS 7.4EG 7.42020-03-09
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
- CVE-2020-22653CRITICALCVSS 9.8EG 9.82023-01-20
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) befo…
- CVE-2020-22659HIGHCVSS 7.5EG 7.52023-01-20
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) befo…
- CVE-2020-23533HIGHCVSS 7.5EG 7.52021-04-06
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (…
- CVE-2020-23967HIGHCVSS 7.8EG 7.82021-03-08
Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
- CVE-2020-24429HIGHCVSS 7.7EG 7.72020-11-05
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a signature verification bypass that could result in local privilege escalation. Exploitation …
- CVE-2020-24439LOWCVSS 2.8EG 2.82020-11-05
Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a security feature bypass. While the practical security impact is minimal, a defense-in-depth …
- CVE-2020-25166HIGHCVSS 7.6EG 7.62022-04-14
An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware…
- CVE-2020-25490HIGHCVSS 7.3EG 7.32020-09-17
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.
- CVE-2020-26122HIGHCVSS 7.2EG 7.22020-12-07
Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in checking the firmware and lacks the signatur…
- CVE-2020-26244MEDIUMCVSS 6.8EG 6.82020-12-02
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algori…
- CVE-2020-26290CRITICALCVSS 9.3EG 9.32020-12-28
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilities enables potential signature bypass due…
- CVE-2020-26540HIGHCVSS 7.5EG 7.52020-10-02
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
- CVE-2020-27540CRITICALCVSS 9.8EG 9.82021-01-26
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json. fw-sign parameter and from this configuration is directly…
- CVE-2020-28042MEDIUMCVSS 5.3EG 5.32020-11-02
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
- CVE-2020-28045HIGHCVSS 7.8EG 7.82020-11-02
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of Sale application developer and distribut…
- CVE-2020-28086HIGHCVSS 7.5EG 7.52020-12-09
pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the c…
- CVE-2020-29438MEDIUMCVSS 6.5EG 6.52020-11-30
Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construct firmware that retrieves an unlock code from a secure enclave chip.
- CVE-2020-3138MEDIUMCVSS 6.7EG 6.72020-02-19
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature va…
- CVE-2020-3209MEDIUMCVSS 6.8EG 6.82020-06-03
A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability …
- CVE-2020-3308MEDIUMCVSS 4.9EG 4.92020-05-06
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an aff…
- CVE-2020-35169CRITICALCVSS 9.1EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.
- CVE-2020-36284HIGHCVSS 7.5EG 7.52021-04-06
Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) …
- CVE-2020-36285HIGHCVSS 7.5EG 7.52021-04-06
Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (M…
- CVE-2020-36563MEDIUMCVSS 5.3EG 5.32022-12-28
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
- CVE-2020-36843MEDIUMCVSS 4.3EG 4.32025-03-13
The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to…
- CVE-2020-5390HIGHCVSS 7.5EG 7.52020-01-13
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is si…
- CVE-2020-5407HIGHCVSS 8.8EG 8.82020-05-13
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefu…
- CVE-2020-6174CRITICALCVSS 9.8EG 9.82020-02-05
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
- CVE-2020-7906HIGHCVSS 7.5EG 7.52020-01-30
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →