Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-347 (密码学签名的验证不恰当) — Vulnerability Class 466

466 vulnerabilities classified as CWE-347 (密码学签名的验证不恰当). AI Chinese analysis included.

CWE-347 represents a critical integrity weakness where software fails to properly validate cryptographic signatures attached to data or code. Attackers typically exploit this flaw by intercepting communications or modifying stored files, substituting legitimate content with malicious payloads that lack valid digital signatures. Because the application accepts these unsigned or tampered inputs as authentic, it executes unauthorized commands or processes corrupted data, potentially leading to complete system compromise or data loss. To prevent this vulnerability, developers must implement rigorous verification routines that strictly check every incoming or processed item against its expected cryptographic signature using trusted public keys. This ensures that any alteration, even a single bit change, is detected and rejected. Additionally, employing secure key management practices and avoiding custom cryptographic implementations further strengthens the system’s defense against signature forgery and tampering attacks.

MITRE CWE Description
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Common Consequences (1)
Access Control, Integrity, Confidentiality Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands
An attacker could gain access to sensitive data and possibly execute unauthorized code.
Examples (1)
In the following code, a JarFile object is created from a downloaded file.
File f = new File(downloadedFilePath); JarFile jf = new JarFile(f);
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2025-52556 rfc3161-client has insufficient verification for timestamp response signatures — rfc3161-client 7.5AI High AI 2025-06-21
CVE-2025-33069 Windows App Control for Business Security Feature Bypass Vulnerability — Windows 11 Version 24H2 5.1 Medium 2025-06-10
CVE-2025-24015 Deno's AES GCM authentication tags are not verified — deno 9.8AI Critical AI 2025-06-03
CVE-2022-31807 Siemens SiPass integrated AC5102和Siemens SiPass integrated ACC-AP 数据伪造问题漏洞 — Building X - Security Manager Edge Controller (ACC-AP) 6.2 Medium 2025-05-23
CVE-2025-47949 samlify SAML Signature Wrapping attack — samlify 8.8AI High AI 2025-05-19
CVE-2025-47934 OpenPGP.js's message signature verification can be spoofed — openpgpjs 8.2AI High AI 2025-05-19
CVE-2025-20181 Cisco IOS 数据伪造问题漏洞 — IOS 6.8AI Medium AI 2025-05-07
CVE-2025-33074 Azure Functions Remote Code Execution Vulnerability — Azure Functions 7.5 High 2025-04-30
CVE-2025-2866 PDF signature forgery with adbe.pkcs7.sha1 SubFilter — LibreOffice 6.5 - 2025-04-27
CVE-2025-2764 CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability — CPC200-CCPA 8.8 - 2025-04-23
CVE-2025-2763 CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability — CPC200-CCPA 6.8 - 2025-04-23
CVE-2025-43903 Freedesktop Poppler 安全漏洞 — Poppler 4.3 Medium 2025-04-18
CVE-2025-20178 Cisco Secure Network Analytics Privilege Escalation Vulnerability — Cisco Secure Network Analytics 6.0 Medium 2025-04-16
CVE-2025-29915 Suricata af-packet: defrag option can lead to truncated packets affecting visibility — suricata 7.5 High 2025-04-10
CVE-2025-27813 Micro-Star MSI Center 安全漏洞 — Center 8.1 High 2025-04-10
CVE-2025-31489 MinIO performs incomplete signature validation for unsigned-trailer uploads — minio 6.5AI Medium AI 2025-04-03
CVE-2025-31335 OpenSAML 安全漏洞 — OpenSAML C++ library 4.0 Medium 2025-03-28
CVE-2025-29775 xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment — xml-crypto 9.8 - 2025-03-14
CVE-2025-29774 xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References — xml-crypto 8.8 - 2025-03-14
CVE-2020-36843 EdDSA-Java 安全漏洞 — ed25519-java 4.3 Medium 2025-03-13
CVE-2025-25292 Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) — ruby-saml 9.8 - 2025-03-12
CVE-2025-25291 ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) — ruby-saml 9.8 - 2025-03-12
CVE-2025-20143 Cisco IOS XR Software Secure Boot Bypass Vulnerability — Cisco IOS XR Software 6.7 Medium 2025-03-12
CVE-2025-2233 Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability — SmartThings 8.8 - 2025-03-11
CVE-2025-27773 SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding — saml2 8.6 High 2025-03-11
CVE-2025-24043 WinDbg Remote Code Execution Vulnerability — WinDbg 7.5 High 2025-03-11
CVE-2025-20206 Cisco Secure Client for Windows with VPN Posture (HostScan) Module DLL Hijacking Vulnerability — Cisco Secure Client 7.1 High 2025-03-05
CVE-2024-11957 Arbitrary Code Execution in WPS Office — WPS Office 7.8 - 2025-03-04
CVE-2025-27498 AEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failure — AEADs 7.5 - 2025-03-03
CVE-2023-25574 JupyterHub's LTI13Authenticator: JWT signature not validated — ltiauthenticator 10.0 Critical 2025-02-25

Vulnerabilities classified as CWE-347 (密码学签名的验证不恰当) represent 466 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.