CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

743 vulnerabilities with CWE-347
CVE-2024-45409 CRITICAL
ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
CVSS 10.0
CVE-2024-38807 MEDIUM
Spring Boot Loader 2.7.0-2.7.21, 3.0.0-3.0.16, 3.1.0-3.1.12, 3.2.0-3.2.8, 3.3.0-3.3.2 - Signature Forgery
CVSS 6.3
CVE-2024-6800 CRITICAL
GitHub Enterprise Server 3.10.0-3.10.15 - Unauthenticated XML Signature Wrapping via SAML Federation Metadata
CVSS 9.8
CVE-2024-23460 MEDIUM
Zscaler Client Connector < 4.2 - Unauthenticated Arbitrary Code Execution via Unsigned Installer
CVSS 6.4
CVE-2024-23456 HIGH
Zscaler Client Connector < 4.2.0.190 - Improper Verification of Cryptographic Signature
CVSS 7.8
CVE-2024-42461 CRITICAL
elliptic 6.5.6 - Improper Verification of Cryptographic Signature via BER-Encoded ECDSA Signatures
CVSS 9.1
CVE-2024-42459 MEDIUM
elliptic 6.5.6 - Improper Verification of Cryptographic Signature via Missing EDDSA Length Check
CVSS 5.3
CVE-2024-41258 MEDIUM
filestash < 0.4 - Man-in-the-Middle Attack via Insecure SSH Host Key Verification
CVSS 5.3
CVE-2024-41254 MEDIUM
litestream < 0.3.13 - Man-in-the-Middle Attack via Insecure SSH Host Key Verification
CVSS 5.3
CVE-2024-5912 MEDIUM
Palo Alto Networks Cortex XDR - Code Injection
CVE-2024-38069 HIGH
Windows Enroll Engine - Privilege Escalation
CVSS 7.0
CVE-2024-6580 MEDIUM
IPWorks SSH <24.0.8945 - Path Traversal
CVSS 6.5
CVE-2024-20892 MEDIUM
Samsung Android - Improper Verification of Cryptographic Signature in FilterProvider
CVSS 6.5
CVE-2024-37532 HIGH
IBM WebSphere Application Server 8.5/9.0 - Identity Spoofing via Cryptographic Validation Flaw
CVSS 8.8
CVE-2024-36277 MEDIUM
FreeFrom - the nostr client App < 1.3.5 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2024-21988 MEDIUM
StorageGRID <11.7.0.9, 11.8.0.5 - Info Disclosure
CVSS 5.3
CVE-2024-37886 MEDIUM
Nextcloud user_oidc < 1.3.5 - Improper Verification of Cryptographic Signature
CVSS 5.4
CVE-2024-32911 CRITICAL
Android - Remote Privilege Escalation via Improper Cryptographic Algorithm
CVSS 9.8
CVE-2024-37568 HIGH
Authlib < 1.3.1 - Algorithm Confusion in JWT Verification
CVSS 7.5
CVE-2024-2451 MEDIUM
TeamViewer <15.54 - Privilege Escalation
CVSS 6.4
CVE-2024-1721 MEDIUM
HYPR Passwordless < 9.1 - Malicious Software Update via Improper Cryptographic Signature Verification
CVE-2024-27244 MEDIUM
Zoom Workplace VDI App < - Privilege Escalation
CVSS 6.7
CVE-2024-34358 MEDIUM
TYPO3 <9.5.48 ELTS, <10.4.45 ELTS, <11.5.37 LTS, <12.4.15 LTS, <13....
CVSS 5.3
CVE-2024-32962 CRITICAL
xml-crypto 4.0.0-5.9.9 - Improper Verification of Cryptographic Signature via KeyInfo Element
CVSS 10.0
CVE-2024-23480 HIGH
Zscaler Client Connector <4.2 - RCE
CVSS 7.5
Details
Vulnerabilities 743