CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 2 of 33
- CVE-2022-42813CRITICALCVSS 9.8EG 9.82022-11-01
A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously craft…
- CVE-2022-34831CRITICALCVSS 9.8EG 9.82022-09-14
An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process…
- CVE-2022-32563CRITICALCVSS 9.8EG 9.82022-06-10
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticat…
- CVE-2022-26493CRITICALCVSS 9.8EG 9.82022-06-03
Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication…
- CVE-2021-29656CRITICALCVSS 9.8EG 9.82022-02-18
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
- CVE-2022-22885CRITICALCVSS 9.8EG 9.82022-02-16
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
- CVE-2021-40855CRITICALCVSS 9.8EG 9.82022-01-21
The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.
- CVE-2021-33907CRITICALCVSS 9.8EG 9.82021-09-27
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an el…
- CVE-2021-20110CRITICALCVSS 9.8EG 9.82021-07-19
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a…
- CVE-2020-11176CRITICALCVSS 9.8EG 9.82021-06-09
While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow which can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna…
- CVE-2020-28907CRITICALCVSS 9.8EG 9.82021-05-24
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.
- CVE-2021-3406CRITICALCVSS 9.8EG 9.82021-02-25
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
- CVE-2019-8531CRITICALCVSS 9.8EG 9.82020-10-27
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS …
- CVE-2020-24715CRITICALCVSS 9.8EG 9.82020-08-27
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.
- CVE-2020-24714CRITICALCVSS 9.8EG 9.82020-08-27
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.
- CVE-2019-18847CRITICALCVSS 9.8EG 9.82020-08-26
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
- CVE-2020-12637CRITICALCVSS 9.8EG 9.82020-05-09
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
- CVE-2020-1952CRITICALCVSS 9.8EG 9.82020-04-27
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
- CVE-2020-7956CRITICALCVSS 9.8EG 9.82020-01-31
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
- CVE-2019-18826CRITICALCVSS 9.8EG 9.82019-12-16
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not pr…
- CVE-2019-14910CRITICALCVSS 9.8EG 9.82019-12-05
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has e…
- CVE-2010-4533CRITICALCVSS 9.8EG 9.82019-11-13
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
- CVE-2019-18633CRITICALCVSS 9.8EG 9.82019-10-30
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.
- CVE-2019-18632CRITICALCVSS 9.8EG 9.82019-10-30
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.
- CVE-2018-21029CRITICALCVSS 9.8EG 9.82019-10-30
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed…
- CVE-2019-1010275CRITICALCVSS 9.8EG 9.82019-07-17
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see http…
- CVE-2019-10914CRITICALCVSS 9.8EG 9.82019-04-08
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certificate verification because of missing validation in psRsaDecryptPubExt in crypto/pubkey/rsa_p…
- CVE-2018-11747CRITICALCVSS 9.8EG 9.82019-03-21
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be able to provide their own TLS certificat…
- CVE-2019-6266CRITICALCVSS 9.8EG 9.82019-02-25
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns. These issues allow remote attackers to downgrade encrypted connections to cleartext.
- CVE-2018-15387CRITICALCVSS 9.8EG 9.82018-10-05
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit thi…
- CVE-2016-1000030CRITICALCVSS 9.8EG 9.82018-09-05
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appea…
- CVE-2018-12829CRITICALCVSS 9.8EG 9.82018-08-29
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation.
- CVE-2018-4991CRITICALCVSS 9.8EG 9.82018-05-19
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a security bypass.
- CVE-2018-9127CRITICALCVSS 9.8EG 9.82018-04-02
Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should not match. This only affects certificates issued to the same…
- CVE-2017-17301CRITICALCVSS 9.8EG 9.82018-02-15
Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR150 V200R00…
- CVE-2015-2320CRITICALCVSS 9.8EG 9.82018-01-08
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
- CVE-2015-3886CRITICALCVSS 9.8EG 9.82017-07-21
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.
- CVE-2017-7406CRITICALCVSS 9.8EG 9.82017-07-07
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor network traffic to steal a user's credenti…
- CVE-2017-2800CRITICALCVSS 9.8EG 9.82017-05-24
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to…
- CVE-2015-7826CRITICALCVSS 9.8EG 9.82017-04-10
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.…
- CVE-2009-3555CRITICALCVSS 9.8EG 9.82009-11-09
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla N…
- CVE-2021-43882CRITICALCVSS 9.0EG 9.82021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2024-41334CRITICALCVSS 8.8EG 9.82025-02-27
Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 28…
- CVE-2022-45100CRITICALCVSS 8.1EG 9.82023-02-01
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system.
- CVE-2022-32156CRITICALCVSS 8.1EG 9.82022-06-15
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, se…
- CVE-2019-3777CRITICALCVSS 8.0EG 9.82019-03-07
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker tha…
- CVE-2022-26305CRITICALCVSS 7.5EG 9.82022-07-25
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a truste…
- CVE-2022-37437CRITICALCVSS 7.4EG 9.82022-08-16
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects con…
- CVE-2026-57826CRITICALCVSS 6.8EG 9.82026-08-18
An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate CAs are only verified for v3 certificates, and v1/v2 certificates…
- CVE-2019-3807CRITICALCVSS 3.7EG 9.82019-01-29
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to byp…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →