CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
743 vulnerabilities with CWE-347
CVE-2023-28226
MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Security Feature Bypass via Cryptographic Signature Verification
CVSS 5.3
CVE-2023-28818
MEDIUM
Veritas NetBackup IT Analytics <11.2.0 - Code Injection
CVSS 5.3
CVE-2023-28610
CRITICAL
OMICRON StationGuard/StationScout <2.21 - RCE
CVSS 9.8
CVE-2023-28113
MEDIUM
russh <0.36.2-0.37.1 - Info Disclosure
CVSS 5.9
CVE-2023-20940
HIGH
Android 13 - Local Privilege Escalation via Boot Partition Replacement
CVSS 7.8
CVE-2023-25718
CRITICAL
ConnectWise Control < 22.9.10032 - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2023-23940
MEDIUM
OpenZeppelin Contracts for Cairo - Code Injection
CVSS 6.4
CVE-2023-23928
MEDIUM
reason-jose < 0.8.2 - Improper Verification of Cryptographic Signature in JWS Validation
CVSS 5.9
CVE-2023-22742
MEDIUM
libgit2 < 1.4.5 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2023-24025
HIGH
CRYSTALS-DILITHIUM - Info Disclosure
CVSS 7.5
CVE-2022-31807
MEDIUM
Siemens SIPASS Integrated AC5102 (ACC-G2) and ACC-AP Firmware - Improper Firmware Signature Verification
CVSS 6.2
CVE-2022-3864
MEDIUM
Hitachi Energy Relion 650/670/SAM600-IO Firmware - Denial of Service via Tampered Update Package
CVSS 4.5
CVE-2022-25333
HIGH
Texas Instruments OMAP L138 Firmware - Improper Verification of Cryptographic Signature via SK_LOAD Routine
CVSS 8.2
CVE-2022-4418
HIGH
Acronis Cyber Protect Home Office < 40208 - Local Privilege Escalation via Unsigned Library Loading
CVSS 7.8
CVE-2022-20929
HIGH
Cisco Enterprise NFV Infrastructure Software 3.5.1-4.9.1 - Unauthenticated Cryptographic Signature Verification Bypass
CVSS 7.8
CVE-2022-34459
HIGH
Dell Command | Update, Dell Update, Alienware Update < 4.7 - Cryptographic Signature Verification Bypass
CVSS 7.8
CVE-2022-23334
CRITICAL
Ip-label Newtest < 8.5r0 - Privilege Escalation via Weak Binary Signature Check
CVSS 9.8
CVE-2022-46176
MEDIUM
Cargo < 1.66.1 - Improper Verification of Cryptographic Signature via SSH Host Key
CVSS 5.3
CVE-2022-23540
MEDIUM
jsonwebtoken <=8.5.1 - Signature Validation Bypass via Default 'none' Algorithm
CVSS 6.4
CVE-2022-47549
MEDIUM
OP-TEE < 3.20 - Cryptographic Signature Verification Bypass via Electromagnetic Fault Injection
CVSS 6.4
CVE-2022-23507
MEDIUM
tendermint-light-client < 0.28.0 - Improper Verification of Cryptographic Signature
CVSS 5.4
CVE-2022-41669
HIGH
SGIUtility <V3.3 Hotfix 1 - Code Injection
CVSS 7.0
CVE-2022-41666
HIGH
EcoStruxure Operator Terminal Expert <V3.3 Hotfix 1 - Code Injection
CVSS 7.0
CVE-2022-42793
MEDIUM
iPadOS < 15.7 - Improper Verification of Cryptographic Signature
CVSS 5.5
CVE-2022-39366
CRITICAL
DataHub < 0.8.45 - Authentication Bypass via Missing JWT Signature Verification
CVSS 9.9
Details
Vulnerabilities
743