← Back
CWE-347

732 CVEs • Abstraction: Base

Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

JSON object

Loading...

CVEs (732)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
May 2, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per secti...Show more
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`. `xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />` even if library was configured to use specific certificate (`publicCert`) for signature verification purposes. An attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.Show less
1Zscaler
1Client Connector
Jun 17, 2026
May 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
1Zoom
1Zoom
Jun 17, 2026
Apr 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
1Zoom
1Zoom
Jun 17, 2026
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Apr 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Cryptographic Services Security Feature Bypass Vulnerability
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Jun 17, 2026
Apr 9, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
Secure Boot Security Feature Bypass Vulnerability
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Apr 8, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
-
-
Jun 17, 2026
Apr 3, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via we...Show more
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.Show less
-
-
Jun 17, 2026
Mar 19, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be in...Show more
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.Show less
-
-
Mar 14, 2025
Mar 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.
1Svix
1Svix Webhooks
Jun 17, 2026
Feb 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature v...Show more
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues.Show less
1Snowsoftware
1Snow Inventory Agent
Jun 17, 2026
Feb 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
1Snowsoftware
1Snow Inventory Agent
Jun 17, 2026
Feb 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through...Show more
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2. Show less
1Rockwellautomation
1Factorytalk Services Platform
Jun 17, 2026
Jan 31, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of dig...Show more
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.  If exploited, a malicious user could potentially retrieve user information and modify settings without any authentication.Show less
1Microsoft
1Edge Chromium
Jun 17, 2026
Jan 26, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Amazon
1Aws Encryption Sdk
Jul 14, 2026
Jan 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
1Studionetworksolutions
1Sharebrowser
Jun 17, 2026
Jan 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
4Debian
FedoraprojectGnu+1 more
4Active Iq Unified Manager
Debian LinuxFedora+1 more
Jun 17, 2026
Jan 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This fla...Show more
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 12, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.
1Gentoo
1Portage
Jun 3, 2025
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Port...Show more
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.Show less