CWE-347
676 CVEs • Abstraction: Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CVEs (676)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate th...Show more |
This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH...Show more |
omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to by...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreFeb 23, 2026 Oct 16, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In...Show more |
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack". |
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Oct 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur. |
2Fedoraproject Goxmldsig Project2Fedora GoxmldsigNov 21, 2024 Sep 29, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A...Show more |
2Debian Redhat5Ansible Engine Ansible TowerCeph Storage+2 moreNov 21, 2024 Sep 23, 2020 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even whe...Show more |
1Cisco 22Fmc1000 K9 Bios Fmc1000 K9 FirmwareFmc2500 K9 Bios+19 moreNov 21, 2024 Sep 23, 2020 N/A· v4 6.6 MEDIUM· v3 6.9 MEDIUM· v2 A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compr...Show more |
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine. |
CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license fil...Show more |
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux...Show more |
1Qualcomm 28Ipq6018 Firmware Kamorta FirmwareMsm8998 Firmware+25 moreNov 21, 2024 Sep 8, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdra...Show more |
1Ti 1Simplelink Cc2640r2 Software Development Kit Nov 21, 2024 Aug 31, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipp...Show more |
1Oasis Open 1Oasis Digital Signature Services Nov 21, 2024 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signature, when the Inlin...Show more |
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer a...Show more |
1Microsoft 18Windows 10 1507 Windows 10 1607Windows 10 1709+15 moreFeb 23, 2026 Aug 17, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack...Show more |
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. |
1Dp3t Backend Software Development Kit Project 1Dp3t Backend Software Development Kit Nov 21, 2024 Jul 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the sign...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreNov 21, 2024 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more |