Cyber Posture

CWE · MITRE source

CWE-347Improper Verification of Cryptographic Signature

Abstraction: Base · CVEs in our corpus: 653

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (7)AI

Control Title Family Why it addresses this CWE
SC-17Public Key Infrastructure CertificatesSCPKI certificates under an approved policy require cryptographic signature verification on issuance and validation.
SC-20Secure Name/Address Resolution Service (Authoritative Source)SCRequires cryptographic signatures on authoritative data and support for verifying the chain of trust.
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)SCMandates verification of cryptographic signatures (e.g., DNSSEC RRSIG) on resolution responses, addressing missing or bypassed signature checks.
CM-14Signed ComponentsCMRequires verification of digital signatures using organization-approved certificates before installation, directly preventing improper verification of cryptographic signatures.
SA-19Component AuthenticitySAComponent authenticity commonly depends on cryptographic signatures; the control enforces proper verification of those signatures.
SI-7Software, Firmware, and Information IntegritySIIntegrity tools commonly rely on cryptographic signatures whose improper validation this weakness covers.
SR-11Component AuthenticitySRAuthenticity validation commonly relies on cryptographic signature or certificate checks that this control enforces.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2013-3900 KEV7.65.50.74442013-12-11
CVE-2018-01146.67.50.84692018-01-04
CVE-2024-86986.47.70.81262024-09-19
CVE-2024-94875.49.10.60272024-10-10
CVE-2024-470735.29.10.56112024-11-07
CVE-2020-2021 KEV5.110.00.18962020-06-29
CVE-2024-454094.510.00.42422024-09-10
CVE-2025-59718 KEV4.59.80.09392025-12-09
CVE-2020-1464 KEV4.07.80.07862020-08-17
CVE-2020-280423.25.30.35992020-11-02
CVE-2025-252913.29.80.20842025-03-12
CVE-2021-221603.19.80.18532021-05-26
CVE-2025-47827 KEV3.04.60.00952025-06-05
CVE-2020-92832.67.50.18682020-02-20
CVE-2024-329622.610.00.10632024-05-02
CVE-2025-233692.58.80.11782025-01-21
CVE-2020-90472.46.80.17832020-06-26
CVE-2021-338852.410.00.06922021-08-25
CVE-2018-89552.39.80.04942018-10-24
CVE-2025-252922.29.80.04712025-03-12
CVE-2018-123562.19.80.02612018-06-15
CVE-2018-59232.19.80.01542019-03-27
CVE-2019-63182.19.80.01542019-04-11
CVE-2021-371602.19.80.02032021-08-02
CVE-2021-379272.19.80.02142021-09-22