CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,511 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 2 of 31
- CVE-2014-1266HIGHCVSS 7.4EG 7.42014-02-22
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple O…
- CVE-2014-2845MEDIUMCVSS 5.9EG 5.92017-11-15
Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority.
- CVE-2014-2901HIGHCVSS 7.5EG 7.52019-11-21
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
- CVE-2014-2902HIGHCVSS 7.5EG 7.52019-11-21
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
- CVE-2014-3230MEDIUMCVSS 5.9EG 5.92020-01-28
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment…
- CVE-2014-3250MEDIUMCVSS 6.5EG 6.52017-12-11
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Ap…
- CVE-2014-3394MEDIUMCVSS v2 5.0EG 5.02014-10-10
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certifica…
- CVE-2014-3451HIGHCVSS 7.5EG 7.52017-08-18
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
- CVE-2014-3495HIGHCVSS 7.5EG 7.52019-12-13
duplicity 0.6.24 has improper verification of SSL certificates
- CVE-2014-3607MEDIUMCVSS 5.9EG 5.92018-01-08
DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to sp…
- CVE-2014-3706MEDIUMCVSS 5.9EG 5.92017-10-18
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates.
- CVE-2014-7143HIGHCVSS 7.5EG 7.52019-11-12
Python Twisted 14.0 trustRoot is not respected in HTTP client
- CVE-2014-7242MEDIUMCVSS 5.9EG 5.92017-10-18
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obtain sensitive inform…
- CVE-2014-8164CRITICALCVSS 9.1EG 9.12022-07-06
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.
- CVE-2014-8167MEDIUMCVSS 5.9EG 5.92019-11-13
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
- CVE-2015-0210MEDIUMCVSS 5.9EG 5.92017-08-28
wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack.
- CVE-2015-0294HIGHCVSS 7.5EG 7.52020-01-27
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
- CVE-2015-0874MEDIUMCVSS 5.9EG 5.92017-09-26
Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information from encrypted communications via a crafted certificate.
- CVE-2015-0904MEDIUMCVSS 5.9EG 5.92017-07-25
The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.
- CVE-2015-1777MEDIUMCVSS 5.9EG 5.92018-04-12
rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attack…
- CVE-2015-2318HIGHCVSS 8.1EG 8.12018-01-08
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
- CVE-2015-2319HIGHCVSS 7.5EG 7.52018-01-08
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
- CVE-2015-2320CRITICALCVSS 9.8EG 9.82018-01-08
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
- CVE-2015-2330HIGHCVSS 7.5EG 7.52017-03-10
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies.
- CVE-2015-2674MEDIUMCVSS 5.9EG 5.92017-08-09
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
- CVE-2015-2943MEDIUMCVSS 5.9EG 5.92017-09-06
Honda Moto LINC 1.6.1 does not verify SSL certificates.
- CVE-2015-2981MEDIUMCVSS 5.9EG 5.92018-01-12
The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2015-2988HIGHCVSS 7.4EG 7.42017-10-10
Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks.
- CVE-2015-3152MEDIUMCVSS 5.9EG 5.92016-05-16
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-d…
- CVE-2015-3420MEDIUMCVSS 5.9EG 5.92017-09-19
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.
- CVE-2015-3886CRITICALCVSS 9.8EG 9.82017-07-21
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.
- CVE-2015-4000CRITICALCVSS 3.7EG 9.02015-05-21
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewri…
- CVE-2015-4017HIGHCVSS 7.5EG 7.52017-08-25
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
- CVE-2015-4100MEDIUMCVSS 6.8EG 6.82017-12-21
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."
- CVE-2015-4680HIGHCVSS 7.5EG 7.52017-04-05
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
- CVE-2015-4954MEDIUMCVSS 5.9EG 5.92018-03-27
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200.
- CVE-2015-5263HIGHCVSS 8.1EG 8.12017-09-25
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.
- CVE-2015-5619MEDIUMCVSS 5.9EG 5.92017-08-09
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-t…
- CVE-2015-5639HIGHCVSS 7.4EG 7.42017-10-10
niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.
- CVE-2015-5666MEDIUMCVSS 5.9EG 5.92017-09-25
ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.
- CVE-2015-6358MEDIUMCVSS 5.9EG 5.92017-10-12
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging kn…
- CVE-2015-7778MEDIUMCVSS 5.9EG 5.92017-10-10
Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks.
- CVE-2015-7785MEDIUMCVSS 5.9EG 5.92017-09-25
GANMA! App for iOS does not verify SSL certificates.
- CVE-2015-7826CRITICALCVSS 9.8EG 9.82017-04-10
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.…
- CVE-2015-8960HIGHCVSS 8.1EG 8.12016-09-21
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations w…
- CVE-2016-1000030CRITICALCVSS 9.8EG 9.82018-09-05
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appea…
- CVE-2016-1000033LOWCVSS 3.7EG 3.72016-10-25
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
- CVE-2016-10511MEDIUMCVSS 5.9EG 5.92017-09-18
The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitting man-in-the-middle attackers the ability to view an application-only OAuth cli…
- CVE-2016-10534MEDIUMCVSS 5.9EG 5.92018-05-31
electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with Electron. The `--strict-ssl` command line option in electron-packager >= 5.2.1 <= 6.0.0 || >=6.0.0 <= 6.0.2 defaults to…
- CVE-2016-10536MEDIUMCVSS 5.9EG 5.92018-05-31
engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. The vulnerability is related to the way that node.js handles the `rejectUnau…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →