CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

742 vulnerabilities with CWE-347
CVE-2025-27498 MEDIUM
ascon_aead < 0.4.3 - Improper Verification of Cryptographic Signature
CVE-2025-24800 CRITICAL
ismp-grandpa < 15.0.1 - Improper Verification of Cryptographic Signature
CVE-2025-23369 HIGH
GitHub Enterprise Server < 3.12.14 - Improper Verification of Cryptographic Signature
CVSS 8.8
CVE-2025-23206 HIGH
AWS Cloud Development Kit < 2.177.0 - Improper Certificate Validation in OIDC Custom Resource Provider
CVSS 8.1
CVE-2024-23581 MEDIUM
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability
CVSS 6.7
CVE-2024-36334 HIGH
Amd Radeon™ RX 7000 Series Graphics Products - Improper Verification of Cryptographic Signature
CVE-2024-13990 CRITICAL
MicroWorld eScan AV - Unauthenticated Remote Code Execution via Update Mechanism Man-in-the-Middle Attack
CVE-2024-49365 HIGH
tiny-secp256k1 < 1.1.7 - Improper Verification of Cryptographic Signature via Buffer.isBuffer Bypass
CVE-2024-36347 MEDIUM
AMD EPYC 7001/7002/7003/9004/4004/9005, Instinct MI300A, Ryzen 5000 - Cryptographic Signature Verification Bypass
CVSS 6.4
CVE-2024-11957 CRITICAL
Kingsoft WPS Office <=12.1.0.18276 - Code Injection
CVE-2024-10237 HIGH
Supermicro MBD-X12DPG-OA6 - Auth Bypass
CVSS 7.2
CVE-2024-56161 HIGH
AMD EPYC 7001/7002/7003/9004 Series - Authenticated CPU Microcode Patch Loader Signature Verification Bypass
CVSS 7.2
CVE-2024-13172 HIGH
Ivanti Endpoint Manager < 2022 SU6 - Remote Code Execution via Cryptographic Issue
CVSS 7.8
CVE-2024-7344 HIGH
Cs-grp Neo Impact < 10.1.024-20241127 - Signature Verification Bypass
CVSS 8.2
CVE-2024-54150 CRITICAL
xmidt-org/cjwt < 2.3.0 - Cryptographic Signature Verification Bypass via Algorithm Confusion
CVSS 9.1
CVE-2024-43106 HIGH
Microsoft Excel 16.83 - Code Injection
CVSS 7.1
CVE-2024-42220 HIGH
Microsoft Outlook 16.83.3 - Library Injection via Cryptographic Signature Verification Bypass
CVSS 7.1
CVE-2024-42004 HIGH
Microsoft Teams 24046.2813.2770.1094 for macOS - Library Injection via Crafted Library
CVSS 7.1
CVE-2024-41165 HIGH
Microsoft Word 16.83 for macOS - Library Injection via Cryptographic Signature Verification Bypass
CVSS 7.1
CVE-2024-41159 HIGH
Microsoft OneNote 16.83 for macOS - Library Injection via Cryptographic Signature Verification Bypass
CVSS 7.1
CVE-2024-41145 HIGH
Microsoft Teams 24046.2813.2770.1094 - Library Injection via WebView.app Helper App
CVSS 7.1
CVE-2024-41138 HIGH
Microsoft Teams 24046.2813.2770.1094 - Library Injection via com.microsoft.teams2.modulehost.app
CVSS 7.1
CVE-2024-39804 HIGH
Microsoft PowerPoint 16.83 for macOS - Library Injection via Cryptographic Signature Verification Bypass
CVSS 7.1
CVE-2024-22461 HIGH
Dell RecoverPoint for VMs 6.0.x - Command Injection
CVSS 8.8
CVE-2024-54126 HIGH
TP-Link Archer C50 < V4_240917 Authenticated Firmware Signature Bypass
Details
Vulnerabilities 742