CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2025-20248 MEDIUM
Cisco IOS XR Software - Privilege Escalation
CVSS 6.0
CVE-2025-52550 HIGH
Copeland E3 Supervisory Controller Firmware < 2.31f01 - Unauthenticated Firmware Forgery via Unsigned Upgrade Packages
CVSS 7.2
CVE-2025-30064 HIGH
CGM CLININET <= 2025.MS2 - Session Generation via Insufficient JWT Verification
CVE-2025-57801 CRITICAL
gnark < 0.14.0 - Signature Malleability via Improper S Value Verification
CVSS 9.1
CVE-2025-55229 MEDIUM
Windows Certificates - Info Disclosure
CVSS 5.3
CVE-2025-4371 MEDIUM
Lenovo 510 FHD - Privilege Escalation
CVSS 6.8
CVE-2025-40758 HIGH
Mendix SAML Module - Signature Validation Account Hijacking
CVSS 8.7
CVE-2025-54982 CRITICAL
Zscaler Authentication Server < 6.2r - Authentication Abuse via SAML Cryptographic Signature Verification
CVSS 9.6
CVE-2025-8454 CRITICAL
devscripts - Improper Verification of Cryptographic Signature in uscan
CVSS 9.8
CVE-2025-43185 MEDIUM
macOS Sequoia <15.6 - Info Disclosure
CVSS 5.5
CVE-2025-54419 CRITICAL
node-saml < 5.1.0 - Authentication Bypass via SAML Assertion Manipulation
CVSS 10.0
CVE-2025-43023 CRITICAL
HP Linux Imaging and Printing Software - Info Disclosure
CVSS 9.1
CVE-2025-54369 CRITICAL
node-saml < 5.1.0 - Improper Verification of Cryptographic Signature
CVE-2025-23364 MEDIUM
TIA Administrator < 3.0.6 - Improper Verification of Cryptographic Signature
CVSS 6.2
CVE-2025-21004 MEDIUM
Samsung Wear OS - Unauthenticated Device Power-Off via Broadcast Receiver Intent
CVSS 6.2
CVE-2025-32977 CRITICAL
Quest KACE SMA <14.1.101 - Info Disclosure
CVSS 9.6
CVE-2025-52556 CRITICAL
rfc3161-client < 1.0.3 - Improper Verification of Cryptographic Signature
CVE-2025-33069 MEDIUM
App Control for Business - Info Disclosure
CVSS 5.1
CVE-2025-47827 MEDIUM KEV
IGEL OS < 11 - Secure Boot Bypass via Improper Cryptographic Signature Verification
CVSS 4.6
CVE-2025-24015 MEDIUM
Deno 1.46.0-2.1.6 - Improper Verification of Cryptographic Signature in AES-GCM
CVSS 5.3
CVE-2025-47949 HIGH
samlify < 2.10.0 - Signature Wrapping Attack via SAML Response Forgery
CVSS 7.5
CVE-2025-47934 HIGH
OpenPGP.js 5.0.1-5.11.2 & 6.0.0-alpha.0-6.1.0 Signature Verification Spoofing
CVE-2025-4658 CRITICAL
OpenPubkey < 0.10.0 and OPKSSH < 0.5.0 - Authentication Bypass via JWS Signature Verification
CVSS 9.8
CVE-2025-3757 CRITICAL
OpenPubkey < 0.10.0 - Authentication Bypass via JWS Signature Verification
CVSS 9.8
CVE-2025-20181 MEDIUM
Cisco IOS for Catalyst 2960X/2960XR/2960CX/3560CX - Authenticated Arbitrary Code Execution via Boot File Tampering
CVSS 6.8
Details
Vulnerabilities 686