Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An att
Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks crypt
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic sig
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation o
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injectio
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operat
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0.
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to insta
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privi
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privi
Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q al
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communica
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{ci
browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a dec
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial o
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is config
reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This all
russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffi
DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacke
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthen
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execu
Windows Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key veri
libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included uns
Windows Enroll Engine Security Feature Bypass Vulnerability
Mono Authenticode Validation Spoofing Vulnerability
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp
Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verif
borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptog
aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS S
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and bel
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions star
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Message
Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A m
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` doe
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryp
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic auth
wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started