CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2023-23928 MEDIUM
reason-jose < 0.8.2 - Improper Verification of Cryptographic Signature in JWS Validation
CVSS 5.9
CVE-2023-22742 MEDIUM
libgit2 < 1.4.5 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2023-24025 HIGH
CRYSTALS-DILITHIUM - Info Disclosure
CVSS 7.5
CVE-2022-31807 MEDIUM
Siemens SIPASS Integrated AC5102 (ACC-G2) and ACC-AP Firmware - Improper Firmware Signature Verification
CVSS 6.2
CVE-2022-3864 MEDIUM
Hitachi Energy Relion 650/670/SAM600-IO Firmware - Denial of Service via Tampered Update Package
CVSS 4.5
CVE-2022-25333 HIGH
Texas Instruments OMAP L138 Firmware - Improper Verification of Cryptographic Signature via SK_LOAD Routine
CVSS 8.2
CVE-2022-4418 HIGH
Acronis Cyber Protect Home Office < 40208 - Local Privilege Escalation via Unsigned Library Loading
CVSS 7.8
CVE-2022-20929 HIGH
Cisco Enterprise NFV Infrastructure Software 3.5.1-4.9.1 - Unauthenticated Cryptographic Signature Verification Bypass
CVSS 7.8
CVE-2022-34459 HIGH
Dell Command | Update, Dell Update, Alienware Update < 4.7 - Cryptographic Signature Verification Bypass
CVSS 7.8
CVE-2022-23334 CRITICAL
Ip-label Newtest < 8.5r0 - Privilege Escalation via Weak Binary Signature Check
CVSS 9.8
CVE-2022-46176 MEDIUM
Cargo < 1.66.1 - Improper Verification of Cryptographic Signature via SSH Host Key
CVSS 5.3
CVE-2022-23540 MEDIUM
jsonwebtoken <=8.5.1 - Signature Validation Bypass via Default 'none' Algorithm
CVSS 6.4
CVE-2022-47549 MEDIUM
OP-TEE < 3.20 - Cryptographic Signature Verification Bypass via Electromagnetic Fault Injection
CVSS 6.4
CVE-2022-23507 MEDIUM
tendermint-light-client < 0.28.0 - Improper Verification of Cryptographic Signature
CVSS 5.4
CVE-2022-41669 HIGH
SGIUtility <V3.3 Hotfix 1 - Code Injection
CVSS 7.0
CVE-2022-41666 HIGH
EcoStruxure Operator Terminal Expert <V3.3 Hotfix 1 - Code Injection
CVSS 7.0
CVE-2022-42793 MEDIUM
iPadOS < 15.7 - Improper Verification of Cryptographic Signature
CVSS 5.5
CVE-2022-39366 CRITICAL
DataHub < 0.8.45 - Authentication Bypass via Missing JWT Signature Verification
CVSS 9.9
CVE-2022-3322 MEDIUM
Cloudflare WARP Mobile Client < 6.14 - Missing Authorization for Lock Warp Switch Bypass
CVSS 6.7
CVE-2022-39300 HIGH
node-saml < 4.0.0 - Improper Verification of Cryptographic Signature
CVSS 7.7
CVE-2022-31123 MEDIUM
Grafana <9.1.8, <8.5.14 - Auth Bypass
CVSS 6.1
CVE-2022-39299 HIGH
passport-saml < 3.2.2 - Authentication Bypass via SAML Signature Verification Flaw
CVSS 7.4
CVE-2022-20944 MEDIUM
Cisco IOS XE for Catalyst 9200 - Unauthenticated Cryptographic Signature Bypass
CVSS 6.1
CVE-2022-42010 MEDIUM
Freedesktop Dbus < 1.12.24 - Signature Verification Bypass
CVSS 6.5
CVE-2022-39237 MEDIUM
sylabs/sif < 2.8.1 - Use of a Broken or Risky Cryptographic Algorithm in Digital Signature Verification
CVSS 6.3
Details
Vulnerabilities 686