BaseDraft

CWE-347Improper Verification of Cryptographic Signature

Category: other

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Common consequences· 1

  • Access Control / Integrity / Confidentiality — Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands
    An attacker could gain access to sensitive data and possibly execute unauthorized code.

Related CAPEC attack patterns· 2

CAPEC-463CAPEC-475

References

  1. https://cwe.mitre.org/data/definitions/347.html

Exploits (incoming)2

TypeTargetConfidenceTier
AttackPatternSignature Spoofing by Improper Validationcapec-475100%live
AttackPatternPadding Oracle Crypto Attackcapec-463100%live

Compliance frameworks addressing this (incoming)3

TypeTargetConfidenceTier
ComplianceControlowasp_api_top10-api02100%live
ComplianceControlowasp_top10-a08100%live
ComplianceControliso27001-a.8.24100%live

(incoming)72

TypeTargetConfidenceTier
VulnerabilityCVE-2025-12007cve-2025-120070%live
VulnerabilityCVE-2025-12295cve-2025-122950%live
VulnerabilityCVE-2025-15444cve-2025-154440%live
VulnerabilityCVE-2025-2233cve-2025-22330%live
VulnerabilityCVE-2025-23206cve-2025-232060%live
VulnerabilityCVE-2025-23364cve-2025-233640%live
VulnerabilityCVE-2025-23369cve-2025-233690%live
VulnerabilityCVE-2025-25291cve-2025-252910%live
VulnerabilityCVE-2025-25292cve-2025-252920%live
VulnerabilityCVE-2025-2764cve-2025-27640%live
VulnerabilityCVE-2025-27670cve-2025-276700%live
VulnerabilityCVE-2025-27773cve-2025-277730%live
VulnerabilityCVE-2025-27813cve-2025-278130%live
VulnerabilityCVE-2025-32977cve-2025-329770%live
VulnerabilityCVE-2025-33074cve-2025-330740%live
VulnerabilityCVE-2025-36418cve-2025-364180%live
VulnerabilityCVE-2025-3757cve-2025-37570%live
VulnerabilityCVE-2025-40758cve-2025-407580%live
VulnerabilityCVE-2025-40934cve-2025-409340%live
VulnerabilityCVE-2025-43023cve-2025-430230%live
VulnerabilityCVE-2025-4658cve-2025-46580%live
VulnerabilityIGEL OS Use of a Key Past its Expiration Date Vulnerabilitycve-2025-478270%live
VulnerabilityCVE-2025-52648cve-2025-526480%live
VulnerabilityCVE-2025-54419cve-2025-544190%live
VulnerabilityCVE-2025-54982cve-2025-549820%live
VulnerabilityCVE-2025-55278cve-2025-552780%live
VulnerabilityCVE-2025-57801cve-2025-578010%live
VulnerabilityCVE-2025-59334cve-2025-593340%live
VulnerabilityFortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerabilitycve-2025-597180%live
VulnerabilityCVE-2025-59719cve-2025-597190%live

Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Insufficient Verification of Data Authenticity
CWE
Improper Certificate Validation
CWE
Improper Validation of Certificate with Host Mismatch
CWE
Improperly Implemented Security Check for Standard
CWE
Use of a Broken or Risky Cryptographic Algorithm
CWE
Deserialization of Untrusted Data
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.