CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

743 vulnerabilities with CWE-347
CVE-2021-3633 HIGH
Lenovo Driver Management < 2.9.0719.1104 - DLL Preloading Privilege Escalation
CVSS 7.3
CVE-2021-36277 HIGH
Dell Command | Update & Alienware Update < 4.3.0 - Authenticated Arbitrary Code Execution via Cryptographic Bypass
CVSS 7.8
CVE-2021-38195 CRITICAL
libsecp256k1 < 0.5.0 - Improper Verification of Cryptographic Signature via R/S Parameter Overflow
CVSS 9.8
CVE-2021-3680 MEDIUM
showdoc < 2.9.7 - Missing Cryptographic Step
CVSS 4.9
CVE-2021-37160 CRITICAL
HMI3 Control Panel Firmware < 7.2.5.7 - Improper Firmware Signature Verification
CVSS 9.8
CVE-2021-22708 HIGH
Schneider-electric Evlink City Evc1s22p4 Firmware < r8_v3.4.0.1 - Signature Verification Bypass
CVSS 7.2
CVE-2021-26100 MEDIUM
FortiMail < 7.0.0 - Unauthenticated Cryptographic Signature Bypass in Identity-Based Encryption
CVSS 5.9
CVE-2021-24020 HIGH
FortiMail 6.2.0-6.2.7 and 6.4.0-6.4.4 - Unauthenticated Cryptographic Signature Bypass via Hash Digest Tampering
CVSS 7.5
CVE-2021-35039 HIGH
Linux kernel <5.12.14 - Signature Verification
CVSS 7.8
CVE-2021-32738 MEDIUM
js-stellar-sdk < 8.2.3 - Improper Authentication in Utils.readChallengeTx
CVSS 6.5
CVE-2021-23993 MEDIUM
Thunderbird < 78.9.1 - Denial of Service via Crafted OpenPGP Key with Invalid Subkey Self Signature
CVSS 6.5
CVE-2021-23992 MEDIUM
Thunderbird < 78.9.1 - OpenPGP Key User ID Spoofing via Invalid Self Signature
CVSS 4.3
CVE-2021-32685 CRITICAL
tEnvoy < 7.0.3 - Improper Verification of Cryptographic Signature in verifyWithMessage Method
CVSS 9.8
CVE-2021-3196 HIGH
Hitachi ID Bravura Security Fabric 11.0.0-11.1.3 12.0.0-12.0.2 12.1.0 - User Impersonation via SAML Injection
CVSS 8.8
CVE-2021-29500 HIGH
bubble_fireworks < 2021.BUILD-SNAPSHOT - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2021-33054 HIGH
SOGo <2.4.1, <3.x-5.1.1 - Auth Bypass
CVSS 7.5
CVE-2021-28091 HIGH
Lasso < 2.7.0 - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2021-22735 HIGH
homeLYnk Wiser For KNX <V2.60 - RCE
CVSS 7.2
CVE-2021-22734 HIGH
Schneider homeLYnk and spaceLYnk <=2.60 - Remote Code Execution via Signature Bypass
CVSS 7.2
CVE-2021-20487 CRITICAL
IBM Power9 & Scale-Out LC Firmware <fw930.30/op940.20 - Signature Verification Bypass
CVSS 9.1
CVE-2021-22160 CRITICAL
Apache Pulsar < 2.7.1 and 2.7.2 - Unauthenticated Authentication Bypass via JWT None Algorithm
CVSS 9.8
CVE-2021-3445 HIGH
libdnf < 0.60.1 - Remote Code Execution via Altered RPM Package Header
CVSS 7.5
CVE-2021-3421 MEDIUM
rpm < 4.17.0-alpha - RPM Database Corruption via Package Signature Verification Bypass
CVSS 5.5
CVE-2021-29455 HIGH
Grassroot Platform < 1.3.1 - Improper Verification of Cryptographic Signature in JWT Refresh
CVSS 7.5
CVE-2021-29451 CRITICAL
Portofino 5.0.0-5.2.0 - Improper Verification of Cryptographic Signature in JWT
CVSS 9.1
Details
Vulnerabilities 743