CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2021-1366 HIGH
Cisco AnyConnect Secure Mobility Client < 4.9.05042 - Authenticated DLL Hijacking via IPC Channel
CVSS 7.8
CVE-2021-3033 CRITICAL
Palo Alto Networks Prisma Cloud <20.12 - Auth Bypass
CVSS 9.1
CVE-2021-1244 MEDIUM
Cisco IOS XR < 7.0.12 - Authenticated Unsigned Code Execution during Boot Process
CVSS 6.7
CVE-2021-1136 MEDIUM
Cisco NCS540L - Authenticated Code Execution
CVSS 6.7
CVE-2021-21239 MEDIUM
PySAML2 <6.5.0 - Improper Signature Verification
CVSS 6.5
CVE-2021-21238 MEDIUM
PySAML2 < 6.5.0 - Improper Verification of Cryptographic Signature via XML Signature Wrapping
CVSS 6.5
CVE-2020-36843 MEDIUM
EdDSA-Java <0.3.0 - Signature Malleability
CVSS 4.3
CVE-2020-22659 HIGH
Ruckus APs and SmartZone Controllers - Unauthorized Firmware Signature Injection
CVSS 7.5
CVE-2020-22653 CRITICAL
Ruckus APs and SmartZone Controllers - Unauthorized Firmware Signature Injection
CVSS 9.8
CVE-2020-36563 MEDIUM
XML Digital Signatures - Info Disclosure
CVSS 5.3
CVE-2020-35169 CRITICAL
Dell BSAFE <4.1.5-4.5.2 - Info Disclosure
CVSS 9.1
CVE-2020-25166 HIGH
B. Braun SpaceCom < L81 and Data module compactplus A10-A11 - Improper Firmware Signature Verification
CVSS 7.6
CVE-2020-16156 HIGH
Comprehensive Perl Archive Network - Signature Verification Bypass
CVSS 7.8
CVE-2020-16154 HIGH
App::cpanminus <1.7044 - Signature Verification Bypass
CVSS 7.8
CVE-2020-36285 HIGH
Union Pay <= 3.3.12 - Improper Verification of Cryptographic Signature via Crafted Authentication Code
CVSS 7.5
CVE-2020-36284 HIGH
Union Pay < 3.4.93.4.9 - Improper Verification of Cryptographic Signature via NULL Secret Key
CVSS 7.5
CVE-2020-23533 HIGH
Union Pay < 1.2.0 - Improper Verification of Cryptographic Signature via Crafted Authentication Code
CVSS 7.5
CVE-2020-23967 HIGH
Dr.Web Security Space <12 - Privilege Escalation
CVSS 7.8
CVE-2020-27540 CRITICAL
Rostelecom CS-C2SHW 5.0.082.1 - Command Injection
CVSS 9.8
CVE-2020-26290 CRITICAL
Dex < 2.27.0 - Cryptographic Signature Verification Bypass via XML Encoding Issue
CVSS 9.3
CVE-2020-11093 HIGH
Hyperledger Indy <1.12.4 - Privilege Escalation
CVSS 7.5
CVE-2020-28086 HIGH
password-store < 1.7.3 - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2020-26122 HIGH
Inspur M5 Server Firmware - Remote Code Execution via BMC Firmware Signature Verification Bypass
CVSS 7.2
CVE-2020-26244 MEDIUM
Python oic <1.2.1 - Info Disclosure
CVSS 6.8
CVE-2020-29438 MEDIUM
Tesla Model X <2020-11-23 - Code Injection
CVSS 6.5
Details
Vulnerabilities 686