CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

743 vulnerabilities with CWE-347
CVE-2023-28801 CRITICAL
Zscaler Admin UI <6.2 - Privilege Escalation
CVSS 9.6
CVE-2023-36811 MEDIUM
borgbackup < 1.2.5 - Cryptographic Signature Spoofing via Archive Forgery
CVSS 4.7
CVE-2023-20266 MEDIUM
Cisco Emergency Responder, Unified CM, Unity Connection - Privilege Escalation via Crafted Upgrade File
CVSS 6.5
CVE-2023-41037 MEDIUM
OpenPGP.js <5.9.0 - Info Disclosure
CVSS 4.3
CVE-2023-23773 HIGH
Motorola EBTS/MBTS Base Radio Firmware - Authenticated Arbitrary Code Execution via Firmware Update
CVSS 7.2
CVE-2023-23772 HIGH
Motorola MBTS Site Controller Firmware - Authenticated Arbitrary Code Execution via Unsigned Firmware Update
CVSS 7.2
CVE-2023-40178 MEDIUM
node-saml < 4.0.5 - Insufficient Session Expiration via LogoutRequest Reuse
CVSS 5.3
CVE-2023-39393 HIGH
Huawei EMUI and HarmonyOS - Insecure Signature Validation in ServiceWifiResources
CVSS 7.5
CVE-2023-39392 HIGH
Huawei EMUI and HarmonyOS - Insecure Signature Validation in OsuLogin Module
CVSS 7.5
CVE-2023-40012 MEDIUM
uthenticode < 2.0.0 - Missing Extended Key Usage Validation in Certificate Check
CVSS 5.9
CVE-2023-39969 CRITICAL
uthenticode 1.0.9 - Improper Verification of Cryptographic Signature via Full-File Hashing
CVSS 9.0
CVE-2023-39211 HIGH
Zoom Desktop Client <5.15.5 - Info Disclosure
CVSS 8.8
CVE-2023-38418 HIGH
BIG-IP Edge Client Installer - Privilege Escalation
CVSS 7.8
CVE-2023-3347 MEDIUM
Samba 4.17.0-4.17.9 - Improper Enforcement of Message Integrity in SMB2 Packet Signing
CVSS 5.9
CVE-2023-33768 MEDIUM
Belkin Wemo Smart Plug WSP080 <1.2 - DoS
CVSS 6.5
CVE-2023-35373 MEDIUM
Mono 6.12.0 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2023-32449 HIGH
Dell PowerStore < 3.5.0.0-2050321 - Improper Verification of Cryptographic Signature
CVSS 7.2
CVE-2023-34120 HIGH
Zoom <5.14.0 - Privilege Escalation
CVSS 8.7
CVE-2023-28602 LOW
Zoom for Windows <5.13.5 - Code Injection
CVSS 2.8
CVE-2023-33959 HIGH
notaryproject/notation-go < 1.0.0-rc.6 - Improper Verification of Cryptographic Signature
CVSS 8.3
CVE-2023-34205 CRITICAL
Moov signedxml < 1.1.0 - Signature Verification Bypass via Signature Wrapping
CVSS 9.1
CVE-2023-33185 MEDIUM
django-ses < 3.5.0 - Improper Verification of Cryptographic Signature in SESEventWebhookView
CVSS 4.6
CVE-2023-25934 MEDIUM
Dell Elastic Cloud Storage < 3.8.0.2 - Improper Verification of Cryptographic Signature
CVSS 5.9
CVE-2023-1204 MEDIUM
GitLab 10.1-15.10.7, 15.11-15.11.6, 16.0-16.0.1 - Cryptographic Signature Verification Bypass
CVSS 4.3
CVE-2023-28228 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Spoofing via Cryptographic Signature Verification
CVSS 5.5
Details
Vulnerabilities 743