CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 4 of 33
- CVE-2025-56231CRITICALCVSS 9.1EG 9.12025-11-05
Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.
- CVE-2025-7390CRITICALCVSS 9.1EG 9.12025-08-21
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
- CVE-2024-25141CRITICALCVSS 9.1EG 9.12024-02-20
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this i…
- CVE-2023-49312CRITICALCVSS 9.1EG 9.12023-11-26
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection…
- CVE-2023-5422CRITICALCVSS 9.1EG 9.12023-10-16
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not…
- CVE-2023-45613CRITICALCVSS 9.1EG 9.12023-10-09
In JetBrains Ktor before 2.3.5 server certificates were not verified
- CVE-2023-3724CRITICALCVSS 9.1EG 9.12023-07-17
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the s…
- CVE-2022-31733CRITICALCVSS 9.1EG 9.12023-02-03
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integ…
- CVE-2022-43705CRITICALCVSS 9.1EG 9.12022-11-27
In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).
- CVE-2022-31183CRITICALCVSS 9.1EG 9.12022-08-01
fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer certificate verification is skipped, and the connection pro…
- CVE-2014-8164CRITICALCVSS 9.1EG 9.12022-07-06
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.
- CVE-2021-45490CRITICALCVSS 9.1EG 9.12022-03-28
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.
- CVE-2021-33695CRITICALCVSS 9.1EG 9.12021-09-15
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
- CVE-2021-29504CRITICALCVSS 9.1EG 9.12021-06-07
WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI version 0.12.0 and later allows remote attackers able to intercept the communication to remotely disable the certificate …
- CVE-2020-29663CRITICALCVSS 9.1EG 9.12020-12-15
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
- CVE-2020-9868CRITICALCVSS 9.1EG 9.12020-10-22
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, w…
- CVE-2020-16163CRITICALCVSS 9.1EG 9.12020-07-30
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass intended access restrictions, or to tri…
- CVE-2017-18911CRITICALCVSS 9.1EG 9.12020-06-19
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
- CVE-2020-11580CRITICALCVSS 9.1EG 9.12020-04-06
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
- CVE-2019-17560CRITICALCVSS 9.1EG 9.12020-03-30
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code…
- CVE-2020-1887CRITICALCVSS 9.1EG 9.12020-03-13
Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.
- CVE-2020-9434CRITICALCVSS 9.1EG 9.12020-02-27
openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
- CVE-2020-9433CRITICALCVSS 9.1EG 9.12020-02-27
openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
- CVE-2020-9432CRITICALCVSS 9.1EG 9.12020-02-27
openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
- CVE-2020-7043CRITICALCVSS 9.1EG 9.12020-02-27
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.exam…
- CVE-2017-17945CRITICALCVSS 9.1EG 9.12019-06-24
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
- CVE-2017-17944CRITICALCVSS 9.1EG 9.12019-06-20
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
- CVE-2018-5926CRITICALCVSS 9.1EG 9.12019-03-27
A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.
- CVE-2019-8351CRITICALCVSS 9.1EG 9.12019-03-21
Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2019-6592CRITICALCVSS 9.1EG 9.12019-02-26
On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.
- CVE-2026-45389CRITICALCVSS 7.4EG 9.12026-06-15
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authenti…
- CVE-2022-32151CRITICALCVSS 7.4EG 9.12022-06-15
The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud P…
- CVE-2023-50356CRITICALCVSS 6.5EG 9.12024-01-31
SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and pr…
- CVE-2022-34865CRITICALCVSS 4.8EG 9.12022-08-04
In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software ver…
- CVE-2026-82955CRITICALCVSS 9.0EG 9.02026-09-02
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to overri…
- CVE-2025-55109CRITICALCVSS 9.0EG 9.02025-09-16
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote …
- CVE-2025-23114CRITICALCVSS 9.0EG 9.02025-02-05
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
- CVE-2022-20813CRITICALCVSS 9.0EG 9.02022-07-06
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byt…
- CVE-2021-23155CRITICALCVSS 9.0EG 9.02021-11-18
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions p…
- CVE-2020-11050CRITICALCVSS 9.0EG 9.02020-05-07
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
- CVE-2020-27648CRITICALCVSS 8.3EG 9.02020-10-29
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2025-65753CRITICALCVSS 7.5EG 9.02026-02-17
An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.
- CVE-2015-4000CRITICALCVSS 3.7EG 9.02015-05-21
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewri…
- CVE-2026-5787HIGHCVSS 8.9EG 8.92026-05-07
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
- CVE-2024-28872HIGHCVSS 8.9EG 8.92024-07-11
The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agent. Once this connection is established with the valid certificate, the attacker can send m…
- CVE-2026-47632HIGHCVSS 8.8EG 8.82026-07-14
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
- CVE-2026-45170HIGHCVSS 8.8EG 8.82026-06-12
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
- CVE-2026-8992HIGHCVSS 8.8EG 8.82026-05-22
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
- CVE-2026-0233HIGHCVSS 8.8EG 8.82026-04-13
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
- CVE-2026-30840HIGHCVSS 8.8EG 8.82026-03-07
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →