CWE-347

Improper Verification of Cryptographic Signature
AI Translation Available

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Status
draft
Abstraction
base

Common Consequences

access control integrity confidentiality
Impacts
gain privileges or assume identity modify application data execute unauthorized code or commands

Detection Methods

automated static analysis

Potential Mitigations