CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

743 vulnerabilities with CWE-347
CVE-2022-3322 MEDIUM
Cloudflare WARP Mobile Client < 6.14 - Missing Authorization for Lock Warp Switch Bypass
CVSS 6.7
CVE-2022-39300 HIGH
node-saml < 4.0.0 - Improper Verification of Cryptographic Signature
CVSS 7.7
CVE-2022-31123 MEDIUM
Grafana <9.1.8, <8.5.14 - Auth Bypass
CVSS 6.1
CVE-2022-39299 HIGH
passport-saml < 3.2.2 - Authentication Bypass via SAML Signature Verification Flaw
CVSS 7.4
CVE-2022-20944 MEDIUM
Cisco IOS XE for Catalyst 9200 - Unauthenticated Cryptographic Signature Bypass
CVSS 6.1
CVE-2022-42010 MEDIUM
Freedesktop Dbus < 1.12.24 - Signature Verification Bypass
CVSS 6.5
CVE-2022-39237 MEDIUM
sylabs/sif < 2.8.1 - Use of a Broken or Risky Cryptographic Algorithm in Digital Signature Verification
CVSS 6.3
CVE-2022-41340 HIGH
secp256k1-js <1.1.0 - Info Disclosure
CVSS 7.5
CVE-2022-36056 MEDIUM
sigstore/cosign < 1.12.0 - Improper Verification of Cryptographic Signature
CVSS 5.5
CVE-2022-39200 HIGH
Dendrite < 0.9.8 - Improper Verification of Cryptographic Signature via /get_missing_events Endpoint
CVSS 7.3
CVE-2022-2790 MEDIUM
Emerson Electric's Proficy Machine Edition < 9.0.0 - Improper Verification of Cryptographic Signature
CVSS 5.9
CVE-2022-28752 HIGH
Zoom Rooms for Conference Rooms for Windows <5.11.0 - Privilege Esc...
CVSS 8.8
CVE-2022-28751 HIGH
Zoom Client for Meetings <5.11.3 - Privilege Escalation
CVSS 8.8
CVE-2022-28756 HIGH
Zoom Client for Meetings <5.11.5 - Privilege Escalation
CVSS 8.8
CVE-2022-35930 HIGH
PolicyController <0.2.1 - Info Disclosure
CVSS 7.1
CVE-2022-35929 HIGH
sigstore cosign < 1.10.1 - Improper Verification of Cryptographic Signature via Attestation Type Check
CVSS 7.1
CVE-2022-31207 CRITICAL
Omron SYSMAC CS/CJ/CP Series Firmware - Unauthenticated Arbitrary Code Execution via FINS Protocol
CVSS 9.8
CVE-2022-31206 CRITICAL
Omron SYSMAC Nx PLCs < 1.29/1.49 - Unauthenticated Arbitrary Code Execution via Unverified Object Code
CVSS 9.8
CVE-2022-31172 HIGH
OpenZeppelin Contracts <4.7.1 - Code Injection
CVSS 7.5
CVE-2022-31156 MEDIUM
Gradle 6.2.0-7.4.2 - Dependency Verification Bypass via Missing Checksum or Signature
CVSS 6.6
CVE-2022-25898 HIGH
jsrsasign 4.8.0-10.5.24 - Improper Verification of Cryptographic Signature
CVSS 7.7
CVE-2022-1739 MEDIUM
Dominion Voting Systems ImageCast X - Improper Cryptographic Signature Verification
CVSS 6.8
CVE-2022-31053 CRITICAL
Biscuit Authentication Token - Cryptographic Signature Forgery via Gamma-Signature Algorithm
CVSS 9.8
CVE-2022-26510 MEDIUM
InHand Networks InRouter302 V3.5.37 - Code Injection
CVSS 6.5
CVE-2022-24884 CRITICAL
ecdsautils < 0.4.1 - Cryptographic Signature Verification Bypass via Zero Signature Values
CVSS 10.0
Details
Vulnerabilities 743