Umbra Wiki weakness weakness/CWE-347
Back to wiki

CWE-347 — Improper Verification of Cryptographic Signature

provenance: imported · CWE: CWE-347

CWE-347: Improper Verification of Cryptographic Signature

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Common consequences

  • Access Control, Integrity, Confidentiality: Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/347.html
  • CWE list: https://cwe.mitre.org/data/index.html