CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 13 of 33
- CVE-2019-12496HIGHCVSS 7.5EG 7.52019-05-31
An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificates by default.
- CVE-2019-11324HIGHCVSS 7.5EG 7.52019-04-18
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verificatio…
- CVE-2018-4436HIGHCVSS 7.5EG 7.52019-04-03
A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2.
- CVE-2018-6517HIGHCVSS 7.5EG 7.52019-03-21
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts…
- CVE-2019-7728HIGHCVSS 7.5EG 7.52019-02-22
An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certificate checks, a malicious actor could potentially succeed in executing a man-in-the-middle attack for some connections.…
- CVE-2018-20245HIGHCVSS 7.5EG 7.52019-01-23
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
- CVE-2018-1320HIGHCVSS 7.5EG 7.52019-01-07
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully c…
- CVE-2018-17612HIGHCVSS 7.5EG 7.52018-11-09
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which al…
- CVE-2018-15326HIGHCVSS 7.5EG 7.52018-10-31
In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certifica…
- CVE-2018-12608HIGHCVSS 7.5EG 7.52018-09-10
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any do…
- CVE-2018-8034HIGHCVSS 7.5EG 7.52018-08-01
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
- CVE-2016-6562HIGHCVSS 7.5EG 7.52018-07-13
On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to o…
- CVE-2018-1000520HIGHCVSS 7.5EG 7.52018-06-26
ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones shoul…
- CVE-2018-11712HIGHCVSS 7.5EG 7.52018-06-04
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.
- CVE-2018-0227HIGHCVSS 7.5EG 7.52018-04-19
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN c…
- CVE-2018-5466HIGHCVSS 7.5EG 7.52018-03-26
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.
- CVE-2018-5464HIGHCVSS 7.5EG 7.52018-03-26
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.
- CVE-2018-5462HIGHCVSS 7.5EG 7.52018-03-26
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.
- CVE-2018-5502HIGHCVSS 7.5EG 7.52018-03-22
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enable…
- CVE-2017-18227HIGHCVSS 7.5EG 7.52018-03-12
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.
- CVE-2018-7234HIGHCVSS 7.5EG 7.52018-03-09
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.
- CVE-2017-15341HIGHCVSS 7.5EG 7.52018-02-15
Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vulnerability. The software decodes X.509 certificate in an improper way. A remote unauthenticated attacker could send a …
- CVE-2018-0786HIGHCVSS 7.5EG 7.52018-01-10
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NE…
- CVE-2015-2319HIGHCVSS 7.5EG 7.52018-01-08
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
- CVE-2017-3190HIGHCVSS 7.5EG 7.52017-12-16
Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM)…
- CVE-2017-11770HIGHCVSS 7.5EG 7.52017-11-15
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core …
- CVE-2017-7080HIGHCVSS 7.5EG 7.52017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers…
- CVE-2017-1000097HIGHCVSS 7.5EG 7.52017-10-05
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certifica…
- CVE-2017-2299HIGHCVSS 7.5EG 7.52017-09-15
Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir` parameter, a default will be provided…
- CVE-2017-6594HIGHCVSS 7.5EG 7.52017-08-28
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.
- CVE-2015-4017HIGHCVSS 7.5EG 7.52017-08-25
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
- CVE-2014-3451HIGHCVSS 7.5EG 7.52017-08-18
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
- CVE-2017-6664HIGHCVSS 7.5EG 7.52017-08-07
A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the auto…
- CVE-2017-11132HIGHCVSS 7.5EG 7.52017-08-01
An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; therefore the attacker could issue a certificate for the backend and the application would not notice it.
- CVE-2017-7726HIGHCVSS 7.5EG 7.52017-07-11
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
- CVE-2017-4981HIGHCVSS 7.5EG 7.52017-06-14
EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability.
- CVE-2016-8231HIGHCVSS 7.5EG 7.52017-06-04
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
- CVE-2016-3083HIGHCVSS 7.5EG 7.52017-05-30
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x …
- CVE-2017-2498HIGHCVSS 7.5EG 7.52017-05-22
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" component. It allows attackers to bypass intended access restrictions via an untrusted certificate.
- CVE-2017-0248HIGHCVSS 7.5EG 7.52017-05-12
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass V…
- CVE-2016-1132HIGHCVSS 7.5EG 7.52017-04-13
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
- CVE-2017-7192HIGHCVSS 7.5EG 7.52017-04-06
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).
- CVE-2017-5887HIGHCVSS 7.5EG 7.52017-04-06
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).
- CVE-2015-4680HIGHCVSS 7.5EG 7.52017-04-05
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
- CVE-2013-7450HIGHCVSS 7.5EG 7.52017-04-03
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
- CVE-2017-0129HIGHCVSS 7.5EG 7.52017-03-17
Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability."
- CVE-2015-2330HIGHCVSS 7.5EG 7.52017-03-10
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies.
- CVE-2016-7662HIGHCVSS 7.5EG 7.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows remote attackers to spoof certifi…
- CVE-2009-3046HIGHCVSS 7.5EG 7.52009-09-02
Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate.
- CVE-2017-2639HIGHCVSS 6.5EG 7.52018-07-27
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spo…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →