VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 1 of 76
  • CVE-2022-26923HigKEVMay 10, 2022
    risk 0.79cvss 8.8epss 0.83

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2022-20703CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.09

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2023-27823CriMay 12, 2023
    risk 0.71cvss 9.8epss 0.53

    An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

  • CVE-2020-0601HigKEVJan 14, 2020
    risk 0.68cvss 8.1epss 0.89

    A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file…

  • CVE-2017-2800CriMay 24, 2017
    risk 0.67cvss 9.8epss 0.09

    A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the…

  • CVE-2009-3555CriNov 9, 2009
    risk 0.67cvss 9.8epss 0.87

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4…

  • CVE-2026-20184CriApr 15, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior…

  • CVE-2026-2590CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information…

  • CVE-2025-67229CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.

  • CVE-2025-46070CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

  • CVE-2025-6433CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.00

    If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established…

  • CVE-2025-32878CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. Before downloading firmware files, the watch requests some information about the firmware via HTTPS…

  • CVE-2019-20461CriNov 7, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The protocol has been partially reverse engineered. Based upon the reverse engineering, no password or username is ever transferred…

  • CVE-2024-45159CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of…

  • CVE-2024-42395CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete…

  • CVE-2024-20080CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.00

    In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue…

  • CVE-2024-5261CriJun 25, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice…

  • CVE-2024-25140CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no…

  • CVE-2023-51837CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.

  • CVE-2023-42425CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.