CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 20 of 33
- CVE-2022-1834MEDIUMCVSS 6.5EG 6.52022-12-22
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email mess…
- CVE-2022-1632MEDIUMCVSS 6.5EG 6.52022-09-01
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to e…
- CVE-2022-32210MEDIUMCVSS 6.5EG 6.52022-07-14
`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also m…
- CVE-2022-25243MEDIUMCVSS 6.5EG 6.52022-03-10
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_s…
- CVE-2022-25638MEDIUMCVSS 6.5EG 6.52022-02-24
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate…
- CVE-2022-22156MEDIUMCVSS 6.5EG 6.52022-01-19
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may comprom…
- CVE-2021-36756MEDIUMCVSS 6.5EG 6.52021-10-27
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
- CVE-2021-32728MEDIUMCVSS 6.5EG 6.52021-08-18
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.…
- CVE-2021-34558MEDIUMCVSS 6.5EG 6.52021-07-15
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client t…
- CVE-2020-15732MEDIUMCVSS 6.5EG 6.52021-06-22
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefend…
- CVE-2021-24012MEDIUMCVSS 6.5EG 6.52021-06-02
An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.
- CVE-2007-5967MEDIUMCVSS 6.5EG 6.52021-05-17
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
- CVE-2020-36127MEDIUMCVSS 6.5EG 6.52021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability. Through the PUK signature functionality, an administrator will not have access to the current p12 certificate and password. Whe…
- CVE-2021-22511MEDIUMCVSS 6.5EG 6.52021-04-08
Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow unconditionally disabling of SSL/T…
- CVE-2021-28363MEDIUMCVSS 6.5EG 6.52021-03-15
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify t…
- CVE-2021-27257MEDIUMCVSS 6.5EG 6.52021-03-05
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. …
- CVE-2020-12421MEDIUMCVSS 6.5EG 6.52020-07-09
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notificati…
- CVE-2020-4320MEDIUMCVSS 6.5EG 6.52020-06-16
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.
- CVE-2020-13645MEDIUMCVSS 6.5EG 6.52020-05-28
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its in…
- CVE-2019-19101MEDIUMCVSS 6.5EG 6.52020-04-29
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to …
- CVE-2020-7942MEDIUMCVSS 6.5EG 6.52020-02-19
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls ba…
- CVE-2011-2669MEDIUMCVSS 6.5EG 6.52020-01-21
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
- CVE-2019-10444MEDIUMCVSS 6.5EG 6.52019-10-16
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.
- CVE-2019-5280MEDIUMCVSS 6.5EG 6.52019-08-13
The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can perform man-in-the-mi…
- CVE-2019-10382MEDIUMCVSS 6.5EG 6.52019-08-07
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
- CVE-2017-18479MEDIUMCVSS 6.5EG 6.52019-08-05
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
- CVE-2019-3875MEDIUMCVSS 6.5EG 6.52019-06-12
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or throu…
- CVE-2019-10334MEDIUMCVSS 6.5EG 6.52019-06-11
Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.java is used to upload files.
- CVE-2017-12195MEDIUMCVSS 6.5EG 6.52018-07-27
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing aut…
- CVE-2017-7562MEDIUMCVSS 6.5EG 6.52018-07-26
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arb…
- CVE-2018-6219MEDIUMCVSS 6.5EG 6.52018-03-15
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.
- CVE-2018-6374MEDIUMCVSS 6.5EG 6.52018-01-31
The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.
- CVE-2014-3250MEDIUMCVSS 6.5EG 6.52017-12-11
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Ap…
- CVE-2017-7971MEDIUMCVSS 6.5EG 6.52017-09-26
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verific…
- CVE-2013-6662MEDIUMCVSS 6.5EG 6.52017-04-13
Google Chrome caches TLS sessions before certificate validation occurs.
- CVE-2020-7922MEDIUMCVSS 6.4EG 6.52020-04-09
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do no…
- CVE-2025-24471MEDIUMCVSS 6.0EG 6.52025-06-10
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
- CVE-2019-10314MEDIUMCVSS 5.9EG 6.52019-04-30
Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
- CVE-2026-3822MEDIUMCVSS 4.8EG 6.52026-03-09
Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allo…
- CVE-2025-40896MEDIUMCVSS 4.8EG 6.52026-03-04
The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This cou…
- CVE-2017-2629MEDIUMCVSS 4.3EG 6.52018-07-27
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there…
- CVE-2026-73594MEDIUMCVSS 6.4EG 6.42026-09-29
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially e…
- CVE-2026-66760MEDIUMCVSS 6.4EG 6.42026-08-11
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. …
- CVE-2026-12374MEDIUMCVSS 6.4EG 6.42026-07-01
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root vi…
- CVE-2025-23118MEDIUMCVSS 6.4EG 6.42025-03-01
An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.
- CVE-2024-32865MEDIUMCVSS 6.4EG 6.42024-08-01
Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
- CVE-2021-22131MEDIUMCVSS 6.4EG 6.42022-07-18
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve in…
- CVE-2021-20328MEDIUMCVSS 6.4EG 6.42021-02-25
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network posi…
- CVE-2026-81871MEDIUMCVSS 6.3EG 6.32026-09-16
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate e…
- CVE-2026-39828MEDIUMCVSS 6.3EG 6.32026-05-22
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeede…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →