CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2023-39393 HIGH
Huawei EMUI and HarmonyOS - Insecure Signature Validation in ServiceWifiResources
CVSS 7.5
CVE-2023-39392 HIGH
Huawei EMUI and HarmonyOS - Insecure Signature Validation in OsuLogin Module
CVSS 7.5
CVE-2023-40012 MEDIUM
uthenticode < 2.0.0 - Missing Extended Key Usage Validation in Certificate Check
CVSS 5.9
CVE-2023-39969 CRITICAL
uthenticode 1.0.9 - Improper Verification of Cryptographic Signature via Full-File Hashing
CVSS 9.0
CVE-2023-39211 HIGH
Zoom Desktop Client <5.15.5 - Info Disclosure
CVSS 8.8
CVE-2023-38418 HIGH
BIG-IP Edge Client Installer - Privilege Escalation
CVSS 7.8
CVE-2023-3347 MEDIUM
Samba 4.17.0-4.17.9 - Improper Enforcement of Message Integrity in SMB2 Packet Signing
CVSS 5.9
CVE-2023-33768 MEDIUM
Belkin Wemo Smart Plug WSP080 <1.2 - DoS
CVSS 6.5
CVE-2023-35373 MEDIUM
Mono 6.12.0 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2023-32449 HIGH
Dell PowerStore < 3.5.0.0-2050321 - Improper Verification of Cryptographic Signature
CVSS 7.2
CVE-2023-34120 HIGH
Zoom <5.14.0 - Privilege Escalation
CVSS 8.7
CVE-2023-28602 LOW
Zoom for Windows <5.13.5 - Code Injection
CVSS 2.8
CVE-2023-33959 HIGH
notaryproject/notation-go < 1.0.0-rc.6 - Improper Verification of Cryptographic Signature
CVSS 8.3
CVE-2023-34205 CRITICAL
Moov signedxml < 1.1.0 - Signature Verification Bypass via Signature Wrapping
CVSS 9.1
CVE-2023-33185 MEDIUM
django-ses < 3.5.0 - Improper Verification of Cryptographic Signature in SESEventWebhookView
CVSS 4.6
CVE-2023-25934 MEDIUM
Dell Elastic Cloud Storage < 3.8.0.2 - Improper Verification of Cryptographic Signature
CVSS 5.9
CVE-2023-1204 MEDIUM
GitLab 10.1-15.10.7, 15.11-15.11.6, 16.0-16.0.1 - Cryptographic Signature Verification Bypass
CVSS 4.3
CVE-2023-28228 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Spoofing via Cryptographic Signature Verification
CVSS 5.5
CVE-2023-28226 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Security Feature Bypass via Cryptographic Signature Verification
CVSS 5.3
CVE-2023-28818 MEDIUM
Veritas NetBackup IT Analytics <11.2.0 - Code Injection
CVSS 5.3
CVE-2023-28610 CRITICAL
OMICRON StationGuard/StationScout <2.21 - RCE
CVSS 9.8
CVE-2023-28113 MEDIUM
russh <0.36.2-0.37.1 - Info Disclosure
CVSS 5.9
CVE-2023-20940 HIGH
Android 13 - Local Privilege Escalation via Boot Partition Replacement
CVSS 7.8
CVE-2023-25718 CRITICAL
ConnectWise Control < 22.9.10032 - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2023-23940 MEDIUM
OpenZeppelin Contracts for Cairo - Code Injection
CVSS 6.4
Details
Vulnerabilities 686