sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver
user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into acceptin
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatu
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of se
Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verificati
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification,
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature leng
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacke
A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated,
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if t
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically presen
A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED
An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR a
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is a
This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upg
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio
The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privileg
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an a
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of crypt
In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forger
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause Osu
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability m
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started