|
|
|
|
CWE-347 Individual Dictionary Definition (Draft 9)
Weakness ID
| Status: Draft 347 (Weakness Base) | | Description | Summary The software does not verify, or improperly verifies, the cryptographic signature for
data. | | Observed Examples | | Reference | Description |
|---|
| CVE-2002-1796 | Does not properly verify signatures for "trusted" entities. | | CVE-2005-2181 | Insufficient verification allows spoofing. | | CVE-2005-2182 | Insufficient verification allows spoofing. | | CVE-2002-1706 | Accepts a configuration file without a Message Integrity Check (MIC) signature. |
| | Relationships | | | Source Taxonomies | PLOVER - Improperly Verified Signature | | Applicable Platforms | All |
|