CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2023-20568 MEDIUM
Intel Radeon RX Vega M Firmware < 23.10.01.46 - Authenticated Arbitrary Code Execution via Unverified Driver Signature
CVSS 6.7
CVE-2023-20567 MEDIUM
Intel Radeon RX Vega M Firmware < 23.10.01.46 - Arbitrary Code Execution via Improper Signature Verification
CVSS 6.7
CVE-2023-5747 HIGH
HanwhaVision Wave Server Software - Remote Code Execution via Command Injection
CVSS 7.2
CVE-2023-47122 MEDIUM
sigstore gitsign 0.6.0-0.7.x - Improper Verification of Cryptographic Signature via Rekor API
CVSS 4.2
CVE-2023-34058 HIGH
VMware Tools - Privilege Escalation
CVSS 7.1
CVE-2023-46234 MEDIUM
browserify-sign - Signature Forgery
CVSS 6.5
CVE-2023-28804 HIGH
Zscaler Client Connector <1.4.0.105 - Code Injection
CVSS 8.2
CVE-2023-28796 HIGH
Zscaler Client Connector <1.3.1.6 - Code Injection
CVSS 7.1
CVE-2023-46324 HIGH
free5GC udm <1.2.0 - Invalid Curve Attack
CVSS 7.5
CVE-2023-43611 HIGH
BIG-IP Edge Client Installer - Privilege Escalation
CVSS 7.8
CVE-2023-43660 MEDIUM
warpgate < 0.8.1 - Authentication Bypass via Unsigned SSH Key Offer
CVSS 4.8
CVE-2023-42811 MEDIUM
aes-gcm 0.10.0-0.10.2 - Improper Verification of Cryptographic Signature in decrypt_in_place_detached
CVSS 4.7
CVE-2023-42806 MEDIUM
Hydra < 0.13.0 - Cryptographic Signature Verification Bypass via Unsigned CID
CVSS 6.5
CVE-2023-20236 MEDIUM
Cisco IOS XR - Privilege Escalation
CVSS 6.7
CVE-2023-20135 MEDIUM
Cisco IOS XR 7.5.2-7.6 - Authenticated Remote Code Execution via ISO Image Verification Race Condition
CVSS 5.7
CVE-2023-41764 MEDIUM
Microsoft 365 Apps and Office - Spoofing via Improper Cryptographic Signature Verification
CVSS 5.5
CVE-2023-40727 HIGH
QMS Automotive <V12.39 - Code Injection
CVSS 7.8
CVE-2023-41744 HIGH
Acronis Agent and Cyber Protect - Local Privilege Escalation via Unsigned Library Loading
CVSS 7.8
CVE-2023-28801 CRITICAL
Zscaler Admin UI <6.2 - Privilege Escalation
CVSS 9.6
CVE-2023-36811 MEDIUM
borgbackup < 1.2.5 - Cryptographic Signature Spoofing via Archive Forgery
CVSS 4.7
CVE-2023-20266 MEDIUM
Cisco Emergency Responder, Unified CM, Unity Connection - Privilege Escalation via Crafted Upgrade File
CVSS 6.5
CVE-2023-41037 MEDIUM
OpenPGP.js <5.9.0 - Info Disclosure
CVSS 4.3
CVE-2023-23773 HIGH
Motorola EBTS/MBTS Base Radio Firmware - Authenticated Arbitrary Code Execution via Firmware Update
CVSS 7.2
CVE-2023-23772 HIGH
Motorola MBTS Site Controller Firmware - Authenticated Arbitrary Code Execution via Unsigned Firmware Update
CVSS 7.2
CVE-2023-40178 MEDIUM
node-saml < 4.0.5 - Insufficient Session Expiration via LogoutRequest Reuse
CVSS 5.3
Details
Vulnerabilities 686