CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

651 vulnerabilities with CWE-347
CVE-2024-48949 CRITICAL
Indutny Elliptic < 6.5.6 - Signature Verification Bypass
CVSS 9.1
CVE-2024-47832 CRITICAL
SSOReady <7f92a06 - XML Signature Bypass
CVSS 9.8
CVE-2024-23960 MEDIUM
Alpsalpine Ilx-f509 Firmware - Signature Verification Bypass
CVSS 4.6
CVE-2024-7481 HIGH
TeamViewer <15.58.4 - Privilege Escalation
CVSS 8.8
CVE-2024-7479 HIGH
TeamViewer <15.58.4 - Privilege Escalation
CVSS 8.8
CVE-2024-8698 HIGH
Keycloak - Privilege Escalation
CVSS 7.7
CVE-2024-7788 HIGH
Libreoffice < 24.2.5 - Signature Verification Bypass
CVSS 7.8
CVE-2024-45607 MEDIUM
Secreto31126 Whatsapp-api-js < 4.0.3 - Signature Verification Bypass
CVSS 5.8
CVE-2024-45409 CRITICAL
Ruby-SAML <=1.16.0 - Auth Bypass
CVSS 10.0
CVE-2024-38807 MEDIUM
Org.springframework.boot Spring-boot-... - Authentication Bypass by Spoofing
CVSS 6.3
CVE-2024-6800 CRITICAL
GitHub Enterprise Server - SSRF
CVSS 9.8
CVE-2024-23460 MEDIUM
Zscaler Client Connector < 4.2 - Signature Verification Bypass
CVSS 6.4
CVE-2024-23456 HIGH
Zscaler Client Connector < 4.2.0.190 - Signature Verification Bypass
CVSS 7.8
CVE-2024-42461 CRITICAL
Elliptic <6.5.6 - Info Disclosure
CVSS 9.1
CVE-2024-42459 MEDIUM
Elliptic <6.5.6 - Code Injection
CVSS 5.3
CVE-2024-41258 MEDIUM
Filestash < 0.4 - Improper Certificate Validation
CVSS 5.3
CVE-2024-41254 MEDIUM
Litestream < 0.3.13 - IDOR
CVSS 5.3
CVE-2024-5912 MEDIUM
Palo Alto Networks Cortex XDR - Code Injection
CVE-2024-38069 HIGH
Windows Enroll Engine - Privilege Escalation
CVSS 7.0
CVE-2024-6580 MEDIUM
IPWorks SSH <24.0.8945 - Path Traversal
CVSS 6.5
CVE-2024-20892 MEDIUM
Samsung Android - Signature Verification Bypass
CVSS 6.5
CVE-2024-37532 HIGH
IBM Websphere Application Server - Signature Verification Bypass
CVSS 8.8
CVE-2024-36277 MEDIUM
FreeFrom <1.3.5 - Info Disclosure
CVSS 5.3
CVE-2024-21988 MEDIUM
StorageGRID <11.7.0.9, 11.8.0.5 - Info Disclosure
CVSS 5.3
CVE-2024-37886 MEDIUM
Nextcloud User Oidc < 1.3.5 - Signature Verification Bypass
CVSS 5.4
Details
Vulnerabilities 651