CWE-347: Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Last updated
Overview
CWE-347 (Improper Verification of Cryptographic Signature) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
420 recorded CVEs are caused by CWE-347 (Improper Verification of Cryptographic Signature), including 5 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 86 new CWE-347 CVEs have been recorded so far in 2026 (85 in 2025).