Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catal
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catal
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker c
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` func
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a mali
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library m
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthentic
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to
Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM)
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of ho
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of ho
It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 b
showdoc is vulnerable to Missing Cryptographic Step
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may crea
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bug
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulner
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used D
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assert
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA sign
The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signat
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pai
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The ch
Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon C
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity che
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploit
u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) f
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA),
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is ef
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows instal
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN respo
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started