perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The com
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validat
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacke
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run a
User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto,
Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vuln
Veriexec is a kernel-based file integrity subsystem in Junos OS that ensures only authorized binaries are able to be exe
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs
Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to di
Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detect
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.
A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a val
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sig
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.0
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software cou
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with vali
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 20
Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signatur
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially cra
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A mali
A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software coul
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn relea
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the stat
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography librari
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementatio
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an erro
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digit
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earl
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon W
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verifica
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additional
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installatio
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started