Vulnerabilities > Improper Verification of Cryptographic Signature

DATE CVE VULNERABILITY TITLE RISK
2023-10-23 CVE-2023-46324 Improper Verification of Cryptographic Signature vulnerability in Free5Gc UDM
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated.
network
low complexity
free5gc CWE-347
7.5
2023-09-27 CVE-2023-43660 Improper Verification of Cryptographic Signature vulnerability in Warpgate Project Warpgate
Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps.
network
high complexity
warpgate-project CWE-347
8.1
2023-08-31 CVE-2023-41744 Improper Verification of Cryptographic Signature vulnerability in Acronis Agent and Cyber Protect
Local privilege escalation due to unrestricted loading of unsigned libraries.
local
low complexity
acronis CWE-347
7.8
2023-08-31 CVE-2023-28801 Improper Verification of Cryptographic Signature vulnerability in Zscaler Internet Access Admin Portal 6.2
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
network
low complexity
zscaler CWE-347
critical
9.8
2023-08-29 CVE-2023-23772 Improper Verification of Cryptographic Signature vulnerability in Motorola Mbts Site Controller Firmware R05.32.58
Motorola MBTS Site Controller fails to check firmware update authenticity.
network
low complexity
motorola CWE-347
8.8
2023-08-29 CVE-2023-23773 Improper Verification of Cryptographic Signature vulnerability in Motorola Ebts Base Radio Firmware and Mbts Base Radio Firmware
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity.
network
low complexity
motorola CWE-347
8.8
2023-08-22 CVE-2021-43171 Improper Verification of Cryptographic Signature vulnerability in E.Foundation APP Lounge
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.
network
low complexity
e-foundation CWE-347
6.5
2023-08-13 CVE-2023-39392 Improper Verification of Cryptographic Signature vulnerability in Huawei Emui and Harmonyos
Vulnerability of insecure signatures in the OsuLogin module.
network
low complexity
huawei CWE-347
7.5
2023-08-13 CVE-2023-39393 Improper Verification of Cryptographic Signature vulnerability in Huawei Emui and Harmonyos
Vulnerability of insecure signatures in the ServiceWifiResources module.
network
low complexity
huawei CWE-347
7.5
2023-07-13 CVE-2023-33768 Improper Verification of Cryptographic Signature vulnerability in Belkin Wemo Smart Plug Wsp080 Firmware 1.2
Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file.
network
low complexity
belkin CWE-347
6.5