CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2024-1149 HIGH
Snow Inventory Agent <= 6.7.2, <= 6.12.0, <= 6.14.5 - File Manipulation via Snow Update Packages
CVSS 7.8
CVE-2024-21917 CRITICAL
Rockwell Automation FactoryTalk Services Platform < 6.31.00 - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2024-21383 LOW
Microsoft Edge Chromium < 121.0.2277.83 - Spoofing via Cryptographic Signature Verification Bypass
CVSS 3.3
CVE-2024-23680 MEDIUM
AWS Encryption SDK for Java 2.0.0-2.2.0 and <1.9.0 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2024-0567 HIGH
GnuTLS >=3.7.0 <3.8.3 - Denial of Service via Certificate Chain Validation
CVSS 7.5
CVE-2024-21669 CRITICAL
Hyperledger Aries Cloud Agent Python 0.7.0-0.10.4 - Cryptographic Signature Verification Bypass
CVSS 9.9
CVE-2023-53951 CRITICAL
Ever Gauzy 0.281.9 - JWT Authentication Bypass via Weak HMAC Secret
CVSS 9.8
CVE-2023-25574 CRITICAL
jupyterhub-ltiauthenticator 1.3.0-1.4.0 - Improper Verification of Cryptographic Signature in LTI13Authenticator
CVSS 10.0
CVE-2023-28806 MEDIUM
Zscaler Client Connector <4.2.0.190 - Info Disclosure
CVSS 5.7
CVE-2023-34435 HIGH
Realtek rtl819x Jungle SDK v3.4.11 - Arbitrary Firmware Update via Boa formUpload
CVSS 7.2
CVE-2023-50228 HIGH
Parallels Desktop < 19.1.0 (54729) - Local Privilege Escalation via Updater Service Cryptographic Signature Bypass
CVSS 7.8
CVE-2023-52538 CRITICAL
Huawei EMUI and HarmonyOS - Incorrect Authorization in HwIms Module
CVSS 9.1
CVE-2023-52043 HIGH
D-Link COVR 1100, 1102, 1103 - Unauthenticated Network Access via WPA-PSK Password Truncation
CVSS 8.1
CVE-2023-44077 CRITICAL
Studio Network Solutions ShareBrowser <7.0 - Info Disclosure
CVSS 9.8
CVE-2023-2030 LOW
GitLab 12.2-16.5.5, 16.6-16.6.3, 16.7-16.7.1 - Improper Verification of Cryptographic Signature
CVSS 3.5
CVE-2023-5347 CRITICAL
Korenix JetNet Series - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2023-23436 HIGH
Honor MagicOS < 7.1.0.100 - Improper Verification of Cryptographic Signature
CVSS 7.3
CVE-2023-23435 MEDIUM
Honor MagicOS < 7.1.0.137 - Improper Verification of Cryptographic Signature
CVSS 4.0
CVE-2023-23433 MEDIUM
hihonor nth-an00_firmware < 7.0.0.157 - Improper Verification of Cryptographic Signature
CVSS 4.0
CVE-2023-23432 HIGH
hihonor nth-an00_firmware < 7.0.0.157 - Improper Verification of Cryptographic Signature
CVSS 7.3
CVE-2023-23431 HIGH
Hihonor NTH-AN00 Firmware < 7.0.0.157 - Improper Cryptographic Signature Verification
CVSS 7.3
CVE-2023-50714 MEDIUM
yii2-authclient < 2.2.15 - Improper Authentication via OAuth2 PKCE Implementation
CVSS 6.8
CVE-2023-49646 MEDIUM
Zoom Meeting SDK < 5.16.5 - Authenticated Denial of Service
CVSS 6.4
CVE-2023-41337 MEDIUM
h2o <2.3.0-beta2 - SSRF
CVSS 6.1
CVE-2023-49079 CRITICAL
Misskey <2023.11.1-beta.1 - Impersonation
CVSS 9.3
Details
Vulnerabilities 686