CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

743 vulnerabilities with CWE-347
CVE-2020-1464 HIGH KEV
Windows - Spoofing via Improper File Signature Validation
CVSS 7.8
CVE-2020-15827 HIGH
JetBrains ToolBox 1.17-1.17.6856 - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2020-15957 HIGH
DP3T-Backend-SDK < 1.1.1 - Improper Verification of Cryptographic Signature via JWT alg=none Bypass
CVSS 7.5
CVE-2020-15705 MEDIUM
GRUB2 < 2.04 - Secure Boot Bypass via Improper Cryptographic Signature Verification
CVSS 6.4
CVE-2020-10608 HIGH
OSIsoft PI System - Privilege Escalation
CVSS 7.8
CVE-2020-13845 HIGH
Sylabs Singularity 3.0-3.5 - Improper Validation
CVSS 7.5
CVE-2020-15093 HIGH
tough < 0.7.1 - Cryptographic Signature Verification Bypass via Duplicate Signature
CVSS 8.6
CVE-2020-9226 MEDIUM
HUAWEI P30 Firmware < 10.1.0.135(C00E135R2P11) - Improper Cryptographic Signature Verification
CVSS 5.5
CVE-2020-15091 MEDIUM
Tendermint 0.33.0-0.33.6 - Improper Verification of Cryptographic Signature
CVSS 6.5
CVE-2020-2021 CRITICAL KEV
PAN-OS 8.0.x < 8.0.20 - Unauthenticated SAML Authentication Bypass via Improper Signature Verification
CVSS 10.0
CVE-2020-9047 MEDIUM
exacqVision Web Service < 20.06.3.0 and Enterprise Manager < 20.06.4.0 - Authenticated OS Command Injection
CVSS 6.8
CVE-2020-15302 HIGH
Argent RecoveryManager <0xdc350d09f71c48c5D22fBE2741e4d6A03970E192 ...
CVSS 7.5
CVE-2020-14966 HIGH
jsrsasign < 8.0.18 - Cryptographic Signature Verification Bypass via ECDSA Integer Length Malleability
CVSS 7.5
CVE-2020-14199 MEDIUM
Trezor Model T Firmware < 2.3.1 and Trezor One Firmware < 1.9.1 - Improper Verification of Cryptographic Signature
CVSS 6.5
CVE-2020-13895 HIGH
p5-Crypt-Perl < 0.32 - Improper Verification of Cryptographic Signature
CVSS 8.8
CVE-2020-13810 HIGH
Foxit Reader and PhantomPDF < 9.7.2 - Signature Validation Bypass via Modified File
CVSS 7.5
CVE-2020-13803 HIGH
Foxit PhantomPDF and Reader for Mac < 4.0 - Signature Validation Bypass via Modified File
CVSS 7.5
CVE-2020-3209 MEDIUM
Cisco IOS XE - Unauthenticated Digital Signature Verification Bypass
CVSS 6.8
CVE-2020-12607 HIGH
fastecdsa < 2.1.2 - Improper Verification of Cryptographic Signature
CVSS 7.5
CVE-2020-13415 HIGH
Aviatrix Controller <5.1 - Privilege Escalation
CVSS 7.5
CVE-2020-9753 CRITICAL
Whale Browser Installer < 2.6.88.19 - Improper Verification of Cryptographic Signature
CVSS 9.1
CVE-2020-12244 HIGH
PowerDNS Recursor 4.1.0-4.3.0 - DNSSEC Validation Bypass via NXDOMAIN Response
CVSS 7.5
CVE-2020-12046 MEDIUM
Opto 22 SoftPAC Project <= 9.6 - Unauthenticated Firmware Signature Verification Bypass
CVSS 5.7
CVE-2020-12042 MEDIUM
Opto 22 SoftPAC Project <= 9.6 - Arbitrary File Write via Firmware Update Zip Path Traversal
CVSS 6.5
CVE-2020-5407 HIGH
Spring Security 5.2.0-5.2.3 and 5.3.0-5.3.1 - SAML Signature Wrapping via Assertion Injection
CVSS 8.8
Details
Vulnerabilities 743