CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

742 vulnerabilities with CWE-347
CVE-2024-47476 HIGH
Dell NetWorker Management Console <19.11 - Code Injection
CVSS 7.8
CVE-2024-49413 HIGH
SmartSwitch <SMR Dec-2024 Release 1 - Info Disclosure
CVSS 7.1
CVE-2024-52958 HIGH
iota C.ai Conversational Platform <2.1.3 - Code Injection
CVSS 7.2
CVE-2024-53267 MEDIUM
sigstore-java < 1.1.0 - Improper Verification of Cryptographic Signature in KeylessVerifier
CVSS 5.5
CVE-2024-11696 MEDIUM
Mozilla Firefox and Thunderbird - Signature Validation Bypass via Exception Handling
CVSS 5.4
CVE-2024-40592 HIGH
FortiClient MacOS <7.4.0 - Code Injection
CVSS 7.5
CVE-2024-49394 MEDIUM
mutt and neomutt - Cryptographic Signature Bypass via In-Reply-To Header Spoofing
CVSS 5.3
CVE-2024-49393 MEDIUM
mutt and neomutt - Improper Verification of Cryptographic Signature in To and Cc Headers
CVSS 6.5
CVE-2024-47073 CRITICAL
DataEase < 2.10.2 - Improper Verification of Cryptographic Signature for JWT Tokens
CVSS 9.1
CVE-2024-51526 HIGH
HarmonyOS - Improper Verification of Cryptographic Signature in Hidebug Module
CVSS 8.2
CVE-2024-50347 MEDIUM
Laravel Reverb < 1.4.0 - Improper Verification of Cryptographic Signature in Pusher-compatible API
CVE-2024-8036 MEDIUM
ABB Automation Products - Crafted Firmware/Config Denial of Service or Takeover
CVSS 5.9
CVE-2024-48948 MEDIUM
elliptic < 6.6.0 - Improper Verification of Cryptographic Signature via ECDSA Hash Truncation
CVSS 4.8
CVE-2024-47943 CRITICAL
Rittal IoT Interface & CMC III Processing Unit - Code Injection
CVSS 9.8
CVE-2024-8531 HIGH
Data Center Expert - Code Injection
CVSS 7.2
CVE-2024-9487 CRITICAL
GitHub Enterprise Server < 3.11.16 - SAML SSO Authentication Bypass via Cryptographic Signature Verification
CVSS 9.1
CVE-2024-48949 CRITICAL
elliptic < 6.5.6 - Improper Verification of Cryptographic Signature in ECDSA Verify Function
CVSS 9.1
CVE-2024-47832 CRITICAL
SSOReady <7f92a06 - XML Signature Bypass
CVSS 9.8
CVE-2024-23960 MEDIUM
Alpine Halo9 - Improper Verification of Cryptographic Signature in Firmware Metadata
CVSS 4.6
CVE-2024-7481 HIGH
TeamViewer <15.58.4 - Privilege Escalation
CVSS 8.8
CVE-2024-7479 HIGH
TeamViewer <15.58.4 - Privilege Escalation
CVSS 8.8
CVE-2024-8698 HIGH
Keycloak SAML Core < 22.0.13 - Improper Verification of Cryptographic Signature in XMLSignatureUtil
CVSS 7.7
CVE-2024-7788 HIGH
LibreOffice 24.2.0-24.2.4 - Digital Signature Forgery via Zip Repair Mode
CVSS 7.8
CVE-2024-45607 MEDIUM
whatsapp-api-js 4.0.0-4.0.2 - Improper Verification of Cryptographic Signature in verifyRequestSignature
CVSS 5.8
CVE-2024-45409 CRITICAL
ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
CVSS 10.0
Details
Vulnerabilities 742