VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 10 of 76
  • CVE-2024-42193HigApr 15, 2025
    risk 0.53cvss 8.1epss 0.00

    HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead…

  • CVE-2025-1193HigFeb 10, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a…

  • CVE-2024-47258HigFeb 6, 2025
    risk 0.53cvss 8.1epss 0.00

    2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. 2N has currently released an updated version 3.3 of 2N Access Commander, with added Certificate Fingerprint…

  • CVE-2024-40702HigJan 7, 2025
    risk 0.53cvss 8.2epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.

  • CVE-2024-6001HigDec 16, 2024
    risk 0.53cvss 8.1epss 0.00

    An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.

  • CVE-2024-8007HigAug 21, 2024
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could…

  • CVE-2024-29072HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.00

    A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected…

  • CVE-2024-30020HigMay 14, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Cryptographic Services Remote Code Execution Vulnerability

  • CVE-2024-2048HigMar 4, 2024
    risk 0.53cvss 8.1epss 0.00

    Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be…

  • CVE-2023-43017HigFeb 7, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

  • CVE-2023-48427HigDec 12, 2023
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to…

  • CVE-2023-38356HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38355HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38354HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38352HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38351HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-30729HigSep 6, 2023
    risk 0.53cvss 8.1epss 0.00

    Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

  • CVE-2023-38686CriAug 4, 2023
    risk 0.53cvss 9.3epss 0.00

    Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.…

  • CVE-2023-3615HigJul 17, 2023
    risk 0.53cvss 8.1epss 0.00

    Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

  • CVE-2023-31190HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.00

    DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS…