CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 12 of 33
- CVE-2020-12681HIGHCVSS 7.5EG 7.52021-07-26
Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/control the channel by which door lock policies are applied.
- CVE-2021-20109HIGHCVSS 7.5EG 7.52021-07-19
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request …
- CVE-2021-32574HIGHCVSS 7.5EG 7.52021-07-17
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.
- CVE-2021-36377HIGHCVSS 7.5EG 7.52021-07-12
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
- CVE-2021-22909HIGHCVSS 7.5EG 7.52021-05-27
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.
- CVE-2016-20011HIGHCVSS 7.5EG 7.52021-05-25
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
- CVE-2021-32919HIGHCVSS 7.5EG 7.52021-05-13
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certi…
- CVE-2021-29653HIGHCVSS 7.5EG 7.52021-04-22
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
- CVE-2021-27400HIGHCVSS 7.5EG 7.52021-04-22
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
- CVE-2021-21373HIGHCVSS 7.5EG 7.52021-03-26
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS U…
- CVE-2021-20230HIGHCVSS 7.5EG 7.52021-02-23
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a Certificate Authorit…
- CVE-2021-0341HIGHCVSS 7.5EG 7.52021-02-10
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges need…
- CVE-2021-1277HIGHCVSS 7.5EG 7.52021-01-20
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilit…
- CVE-2021-1276HIGHCVSS 7.5EG 7.52021-01-20
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilit…
- CVE-2020-35733HIGHCVSS 7.5EG 7.52021-01-15
An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.
- CVE-2019-16281HIGHCVSS 7.5EG 7.52020-12-30
Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code block.
- CVE-2020-8286HIGHCVSS 7.5EG 7.52020-12-14
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
- CVE-2020-28362HIGHCVSS 7.5EG 7.52020-11-18
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
- CVE-2020-27589HIGHCVSS 7.5EG 7.52020-11-06
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
- CVE-2020-8241HIGHCVSS 7.5EG 7.52020-10-28
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.
- CVE-2019-17007HIGHCVSS 7.5EG 7.52020-10-22
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
- CVE-2020-24560HIGHCVSS 7.5EG 7.52020-09-24
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into d…
- CVE-2020-15604HIGHCVSS 7.5EG 7.52020-09-24
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into d…
- CVE-2020-16162HIGHCVSS 7.5EG 7.52020-07-30
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass i…
- CVE-2019-20894HIGHCVSS 7.5EG 7.52020-07-02
Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.
- CVE-2017-18909HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
- CVE-2020-9040HIGHCVSS 7.5EG 7.52020-06-08
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by J…
- CVE-2020-1113HIGHCVSS 7.5EG 7.52020-05-21
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as…
- CVE-2020-11792HIGHCVSS 7.5EG 7.52020-04-15
NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.
- CVE-2019-3762HIGHCVSS 7.5EG 7.52020-03-18
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certif…
- CVE-2020-7919HIGHCVSS 7.5EG 7.52020-03-16
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
- CVE-2020-9321HIGHCVSS 7.5EG 7.52020-03-16
configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.
- CVE-2019-15604HIGHCVSS 7.5EG 7.52020-02-07
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
- CVE-2015-0294HIGHCVSS 7.5EG 7.52020-01-27
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
- CVE-2020-1929HIGHCVSS 7.5EG 7.52020-01-15
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This ex…
- CVE-2013-0264HIGHCVSS 7.5EG 7.52019-12-30
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
- CVE-2014-3495HIGHCVSS 7.5EG 7.52019-12-13
duplicity 0.6.24 has improper verification of SSL certificates
- CVE-2019-19271HIGHCVSS 7.5EG 7.52019-11-26
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and…
- CVE-2019-19270HIGHCVSS 7.5EG 7.52019-11-26
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from bei…
- CVE-2012-5518HIGHCVSS 7.5EG 7.52019-11-25
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
- CVE-2014-2902HIGHCVSS 7.5EG 7.52019-11-21
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
- CVE-2014-2901HIGHCVSS 7.5EG 7.52019-11-21
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
- CVE-2012-6071HIGHCVSS 7.5EG 7.52019-11-19
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
- CVE-2014-7143HIGHCVSS 7.5EG 7.52019-11-12
Python Twisted 14.0 trustRoot is not respected in HTTP client
- CVE-2019-15042HIGHCVSS 7.5EG 7.52019-10-01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
- CVE-2019-11497HIGHCVSS 7.5EG 7.52019-09-10
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the certificate signature. It then accepted the invalid certificate and attempted to use it t…
- CVE-2016-10937HIGHCVSS 7.5EG 7.52019-09-08
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
- CVE-2019-10381HIGHCVSS 7.5EG 7.52019-08-07
Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
- CVE-2019-1006HIGHCVSS 7.5EG 7.52019-07-15
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vul…
- CVE-2019-13050HIGHCVSS 7.5EG 7.52019-06-29
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data …
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →