CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2022-21134 HIGH
Reolink RLC-410W Firmware 3.0.0.136_20121102 - Firmware Update Signature Bypass via HTTP Request
CVSS 7.5
CVE-2021-1461 MEDIUM
Cisco Catalyst SD-WAN Manager - Authenticated Digital Signature Verification Bypass via Patch Image
CVSS 4.9
CVE-2021-43171 MEDIUM
/e/OS App Lounge <0.19q - Code Injection
CVSS 6.5
CVE-2021-43074 MEDIUM
FortiProxy < 2.0.8 - Improper Verification of Cryptographic Signature
CVSS 4.3
CVE-2021-36226 CRITICAL
Western Digital My Cloud <OS5 - Info Disclosure
CVSS 9.8
CVE-2021-26391 HIGH
AMD Enterprise Driver - Improper Verification of Cryptographic Signature
CVSS 7.8
CVE-2021-35113 HIGH
Qualcomm Firmware - Authentication Bypass via Improper Cryptographic Signature Verification
CVSS 7.3
CVE-2021-35097 HIGH
Qualcomm AQT1000 Firmware - Authentication Bypass via Improper Signature Verification Order
CVSS 7.3
CVE-2021-40326 MEDIUM
Foxit PDF Editor 11.0-11.1, Reader 11.0-11.1, PhantomPDF <10.1.6 - Arbitrary File Write
CVSS 5.5
CVE-2021-3521 MEDIUM
rpm < 4.17.1 - Improper Verification of Cryptographic Signature
CVSS 4.7
CVE-2021-22573 HIGH
Google OAuth Client Library for Java < 1.33.3 - Improper Verification of Cryptographic Signature
CVSS 8.7
CVE-2021-32977 HIGH
AVEVA System Platform <2020 R2 P01 - Info Disclosure
CVSS 7.2
CVE-2021-30066 MEDIUM
Belden Tofino Xenon Security Appliance Firmware < 03.2.03 - Signature Verification Bypass
CVSS 6.8
CVE-2021-20319 HIGH
coreos-installer < 0.10.1 - Improper Verification of Cryptographic Signature via Crafted Gzip Image
CVSS 7.8
CVE-2021-43393 MEDIUM
STMicroelectronics STSAFE-J 1.1.4 & J-SAFE3 1.2.5 - ECDSA Signature Verification Bypass
CVSS 6.2
CVE-2021-43392 MEDIUM
STMicroelectronics STSAFE-J 1.1.4, J-SIGN - Info Disclosure
CVSS 6.2
CVE-2021-25636 HIGH
LibreOffice 7.2.0-7.2.4 - Improper Certificate Validation via Manipulated KeyInfo Tag
CVSS 7.5
CVE-2021-40045 MEDIUM
Huawei EMUI and HarmonyOS < 2.0 - Improper Verification of Cryptographic Signature in Recovery Mode Upgrade
CVSS 5.5
CVE-2021-44878 HIGH
pac4j < 4.5.5 - Improper Verification of Cryptographic Signature via OpenID Connect 'none' Algorithm
CVSS 7.5
CVE-2021-20156 MEDIUM
Trendnet TEW-827DRU 2.08B01 - Improper Firmware Signature Verification
CVSS 6.5
CVE-2021-0152 MEDIUM
Intel(R) Wireless Bluetooth(R) - DoS
CVSS 5.5
CVE-2021-34420 MEDIUM
Zoom Client for Meetings < 5.4.4 - Improper Verification of Cryptographic Signature
CVSS 4.7
CVE-2021-43572 CRITICAL
Stark Bank Python ECDSA <2.0.1 - Code Injection
CVSS 9.8
CVE-2021-43571 CRITICAL
Stark Bank Node.js ECDSA <1.1.2 - Code Injection
CVSS 9.8
CVE-2021-43570 CRITICAL
Stark Bank Java ECDSA <1.0.0 - Code Injection
CVSS 9.8
Details
Vulnerabilities 686