CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 11 of 33
- CVE-2024-45234HIGHCVSS 7.5EG 7.52024-08-24
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses …
- CVE-2024-41264HIGHCVSS 7.5EG 7.52024-08-01
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
- CVE-2024-41255HIGHCVSS 7.5EG 7.52024-07-31
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
- CVE-2024-39698HIGHCVSS 7.5EG 7.52024-07-09
electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` implements the signature validation routine for Electron applications on Windows. Because o…
- CVE-2024-31872HIGHCVSS 7.5EG 7.52024-04-10
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.
- CVE-2024-31871HIGHCVSS 7.5EG 7.52024-04-10
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.
- CVE-2024-27323HIGHCVSS 7.5EG 7.52024-04-01
PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interactio…
- CVE-2023-40104HIGHCVSS 7.5EG 7.52024-02-15
In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not ne…
- CVE-2023-32330HIGHCVSS 7.5EG 7.52024-02-07
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.
- CVE-2023-51662HIGHCVSS 7.5EG 7.52023-12-22
The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks a…
- CVE-2009-4123HIGHCVSS 7.5EG 7.52023-12-12
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
- CVE-2023-49247HIGHCVSS 7.5EG 7.52023-12-06
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-5909HIGHCVSS 7.5EG 7.52023-11-30
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
- CVE-2023-42532HIGHCVSS 7.5EG 7.52023-11-07
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
- CVE-2023-46724HIGHCVSS 7.5EG 7.52023-11-01
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Ce…
- CVE-2023-4499HIGHCVSS 7.5EG 7.52023-10-13
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnera…
- CVE-2023-4801HIGHCVSS 7.5EG 7.52023-09-13
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM se…
- CVE-2023-21265HIGHCVSS 7.5EG 7.52023-08-14
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-38325HIGHCVSS 7.5EG 7.52023-07-14
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
- CVE-2023-30222HIGHCVSS 7.5EG 7.52023-06-16
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
- CVE-2022-45458HIGHCVSS 7.5EG 7.52023-05-18
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) bef…
- CVE-2022-45457HIGHCVSS 7.5EG 7.52023-05-18
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.
- CVE-2023-0464HIGHCVSS 7.5EG 7.52023-03-22
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a …
- CVE-2023-23131HIGHCVSS 7.5EG 7.52023-02-01
Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.
- CVE-2022-45197HIGHCVSS 7.5EG 7.52022-12-25
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.
- CVE-2022-45391HIGHCVSS 7.5EG 7.52022-11-15
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
- CVE-2022-38666HIGHCVSS 7.5EG 7.52022-11-15
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.
- CVE-2022-20960HIGHCVSS 7.5EG 7.52022-11-04
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper …
- CVE-2021-29755HIGHCVSS 7.5EG 7.52022-07-20
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
- CVE-2020-16093HIGHCVSS 7.5EG 7.52022-07-18
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
- CVE-2022-27782HIGHCVSS 7.5EG 7.52022-06-02
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if …
- CVE-2020-26184HIGHCVSS 7.5EG 7.52022-06-01
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
- CVE-2022-24901HIGHCVSS 7.5EG 7.52022-05-04
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL …
- CVE-2022-27536HIGHCVSS 7.5EG 7.52022-04-20
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
- CVE-2022-28142HIGHCVSS 7.5EG 7.52022-03-29
Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues.
- CVE-2021-3698HIGHCVSS 7.5EG 7.52022-03-10
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless …
- CVE-2022-25640HIGHCVSS 7.5EG 7.52022-02-24
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
- CVE-2021-25636HIGHCVSS 7.5EG 7.52022-02-24
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Valida…
- CVE-2021-43114HIGHCVSS 7.5EG 7.52021-11-09
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
- CVE-2021-29737HIGHCVSS 7.5EG 7.52021-11-02
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.
- CVE-2021-41611HIGHCVSS 7.5EG 7.52021-10-18
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security t…
- CVE-2021-25634HIGHCVSS 7.5EG 7.52021-10-12
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Valida…
- CVE-2021-25633HIGHCVSS 7.5EG 7.52021-10-11
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Valida…
- CVE-2021-35497HIGHCVSS 7.5EG 7.52021-10-05
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL …
- CVE-2021-38864HIGHCVSS 7.5EG 7.52021-09-23
IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.
- CVE-2021-27018HIGHCVSS 7.5EG 7.52021-08-30
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured t…
- CVE-2020-36478HIGHCVSS 7.5EG 7.52021-08-23
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if th…
- CVE-2021-37698HIGHCVSS 7.5EG 7.52021-08-19
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter an…
- CVE-2021-22926HIGHCVSS 7.5EG 7.52021-08-05
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library S…
- CVE-2021-35193HIGHCVSS 7.5EG 7.52021-07-30
Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version). This provides remote access to SQL database cre…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →