← Back
CWE-347

675 CVEs • Abstraction: Base

Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

JSON object

Loading...

CVEs (675)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoom
1Workplace Virtual Desktop Infrastructure
Aug 21, 2025
May 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
1Typo3
1Typo3
Sep 3, 2025
May 14, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks...Show more
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&...&frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.Show less
1Parallels
1Parallels Desktop
Aug 8, 2025
May 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels...Show more
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. . Was ZDI-CAN-21817.Show less
-
-
Nov 21, 2024
May 2, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per secti...Show more
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`. `xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />` even if library was configured to use specific certificate (`publicCert`) for signature verification purposes. An attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.Show less
1Zscaler
1Client Connector
Feb 17, 2026
May 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
1Zoom
1Zoom
Jul 31, 2025
Apr 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
1Zoom
1Zoom
Jul 31, 2025
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jan 8, 2025
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Cryptographic Services Security Feature Bypass Vulnerability
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Jan 8, 2025
Apr 9, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
Secure Boot Security Feature Bypass Vulnerability
1Huawei
2Emui
Harmonyos
Mar 25, 2025
Apr 8, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
-
-
Nov 21, 2024
Apr 3, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via we...Show more
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.Show less
-
-
Nov 21, 2024
Mar 19, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be in...Show more
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.Show less
-
-
Mar 14, 2025
Mar 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.
1Svix
1Svix Webhooks
May 9, 2025
Feb 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature v...Show more
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues.Show less
1Snowsoftware
1Snow Inventory Agent
Nov 21, 2024
Feb 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
1Snowsoftware
1Snow Inventory Agent
Nov 21, 2024
Feb 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through...Show more
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2. Show less
1Rockwellautomation
1Factorytalk Services Platform
Jan 15, 2026
Jan 31, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of dig...Show more
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.  If exploited, a malicious user could potentially retrieve user information and modify settings without any authentication.Show less
1Microsoft
1Edge Chromium
Nov 21, 2024
Jan 26, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Amazon
1Aws Encryption Sdk
Nov 29, 2025
Jan 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
1Studionetworksolutions
1Sharebrowser
Jun 17, 2025
Jan 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.