CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2021-43569 CRITICAL
Stark Bank .NET ECDSA <1.3.1 - Code Injection
CVSS 9.8
CVE-2021-43568 CRITICAL
Stark Bank Elixir ECDSA <1.0.0 - Code Injection
CVSS 9.8
CVE-2021-39909 MEDIUM
GitLab 11.3.0-14.2.5, 14.3.0-14.3.3, 14.4.0 - CODEOWNERS Approval Bypass via Email Address Verification Lack
CVSS 5.3
CVE-2021-37127 HIGH
Huawei Imanager Neteco 6000 Firmware - Signature Verification Bypass
CVSS 7.2
CVE-2021-41832 HIGH
Apache OpenOffice < 4.1.11 - Cryptographic Signature Verification Bypass
CVSS 7.5
CVE-2021-41831 MEDIUM
Apache OpenOffice < 4.1.11 - Cryptographic Signature Timestamp Manipulation
CVSS 5.3
CVE-2021-41830 HIGH
Apache OpenOffice < 4.1.11 - Cryptographic Signature Verification Bypass
CVSS 7.5
CVE-2021-29108 HIGH
Esri Portal for ArcGIS < 10.9 - Authenticated Privilege Escalation via SAML Assertion XML Signature Wrapping
CVSS 8.8
CVE-2021-37927 CRITICAL
ManageEngine ADManager Plus <= 7110 - Account Takeover via SSO
CVSS 9.8
CVE-2021-31847 HIGH
McAfee Agent < 5.7.4 - DLL Preloading Privilege Escalation via Unprotected Repair Directory
CVSS 8.2
CVE-2021-31841 HIGH
McAfee Agent < 5.7.4 - DLL Sideloading via Unsigned DLL
CVSS 8.2
CVE-2021-34709 MEDIUM
Cisco IOS XR < 7.3.2 - Authenticated Arbitrary Code Execution via Image Verification Bypass
CVSS 6.0
CVE-2021-34708 MEDIUM
Cisco IOS XR < 7.3.2 - Authenticated Arbitrary Code Execution via Image Verification Bypass
CVSS 6.0
CVE-2021-3051 HIGH
Cortex XSOAR <5.5.0-6.2.0 - Info Disclosure
CVSS 8.1
CVE-2021-1849 HIGH
iPadOS < 14.5 - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2021-33885 CRITICAL
B. Braun SpaceCom2 < 012U000062 - Unauthenticated Insufficient Verification of Data Authenticity
CVSS 10.0
CVE-2021-34433 HIGH
Eclipse Californium <2.6.4 & 3.0.0-M1-M3 - SSL/TLS Verification Bypass
CVSS 7.5
CVE-2021-34715 MEDIUM
Cisco Expressway and TelePresence VCS - Authenticated Remote Code Execution via Upgrade Package
CVSS 4.7
CVE-2021-3633 HIGH
Lenovo Driver Management < 2.9.0719.1104 - DLL Preloading Privilege Escalation
CVSS 7.3
CVE-2021-36277 HIGH
Dell Command | Update & Alienware Update < 4.3.0 - Authenticated Arbitrary Code Execution via Cryptographic Bypass
CVSS 7.8
CVE-2021-38195 CRITICAL
libsecp256k1 < 0.5.0 - Improper Verification of Cryptographic Signature via R/S Parameter Overflow
CVSS 9.8
CVE-2021-3680 MEDIUM
showdoc < 2.9.7 - Missing Cryptographic Step
CVSS 4.9
CVE-2021-37160 CRITICAL
HMI3 Control Panel Firmware < 7.2.5.7 - Improper Firmware Signature Verification
CVSS 9.8
CVE-2021-22708 HIGH
Schneider-electric Evlink City Evc1s22p4 Firmware < r8_v3.4.0.1 - Signature Verification Bypass
CVSS 7.2
CVE-2021-26100 MEDIUM
FortiMail < 7.0.0 - Unauthenticated Cryptographic Signature Bypass in Identity-Based Encryption
CVSS 5.9
Details
Vulnerabilities 686