Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature wi
The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contain
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the
Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulne
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sur
`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation im
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker w
The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT
node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypa
An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Versio
If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) d
A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the Sig
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signa
Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification
Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the
AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic sign
cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive i
PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 Pol
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon
The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root cer
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disab
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow
A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TE
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sy
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptogr
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.
A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerab
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryp
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental
Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, mac
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior t
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started