CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2025-33074 HIGH
Microsoft Azure Functions - Code Injection
CVSS 7.5
CVE-2025-2866 MEDIUM
LibreOffice 24.8.0.1-24.8.5.99 & 25.2.0-25.2.1 PDF Signature Spoofing
CVSS 5.5
CVE-2025-2764 HIGH
CarlinKit CPC200-CCPA - Unauthenticated Remote Code Execution via update.cgi Cryptographic Signature Bypass
CVSS 8.0
CVE-2025-2763 MEDIUM
CarlinKit CPC200-CCPA - Unauthenticated Code Execution via USB Update Package
CVSS 6.8
CVE-2025-43903 MEDIUM
Poppler < 25.04.0 - Improper Verification of Cryptographic Signature
CVSS 4.3
CVE-2025-20178 MEDIUM
Cisco Secure Network Analytics - RCE
CVSS 6.0
CVE-2025-29915 HIGH
Suricata < 7.0.9 - Improper Verification of Cryptographic Signature via AF_PACKET Defrag Option
CVSS 7.5
CVE-2025-27813 HIGH
MSI Center <2.0.52.0 - Privilege Escalation
CVSS 8.1
CVE-2025-31489 HIGH
MinIO - Incomplete Signature Validation for Unsigned-Trailer Uploads
CVE-2025-31335 MEDIUM
OpenSAML C++ < 3.3.1 - Signed SAML Message Forgery
CVSS 4.0
CVE-2025-29775 CRITICAL
xml-crypto < 6.0.1, 3.0.0-3.2.1, < 2.1.6 - Cryptographic Signature Verification Bypass
CVE-2025-29774 CRITICAL
xml-crypto < 6.0.1, 3.0.0-3.2.0, < 2.1.6 - Cryptographic Signature Verification Bypass
CVE-2025-25292 CRITICAL
ruby-saml <1.12.4,1.18.0 - Auth Bypass
CVSS 9.8
CVE-2025-25291 CRITICAL
ruby-saml <1.12.4,1.18.0 - Auth Bypass
CVSS 9.8
CVE-2025-20143 MEDIUM
Cisco IOS XR - Privilege Escalation
CVSS 6.7
CVE-2025-2233 HIGH
Samsung SmartThings < 0.55.5 - Unauthenticated Authentication Bypass via Cryptographic Signature Verification
CVSS 8.8
CVE-2025-27773 HIGH
SimpleSAMLphp saml2 < 4.17.0 and 5.0.0-alpha.1-5.0.0-alpha.20 - Signature Confusion Attack via HTTPRedirect Binding
CVSS 8.6
CVE-2025-24043 HIGH
Windbg < 1.2502.25002.0 - Remote Code Execution via Cryptographic Signature Verification Bypass
CVSS 7.5
CVE-2025-20206 HIGH
Cisco Secure Client - DLL Hijacking
CVSS 7.1
CVE-2025-27670 CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Insufficient Signature Validation
CVSS 9.8
CVE-2025-27498 MEDIUM
ascon_aead < 0.4.3 - Improper Verification of Cryptographic Signature
CVE-2025-24800 CRITICAL
ismp-grandpa < 15.0.1 - Improper Verification of Cryptographic Signature
CVE-2025-23369 HIGH
GitHub Enterprise Server < 3.12.14 - Improper Verification of Cryptographic Signature
CVSS 8.8
CVE-2025-23206 HIGH
AWS Cloud Development Kit < 2.177.0 - Improper Certificate Validation in OIDC Custom Resource Provider
CVSS 8.1
CVE-2024-36334 HIGH
Amd Radeon™ RX 7000 Series Graphics Products - Improper Verification of Cryptographic Signature
Details
Vulnerabilities 686