VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 11 of 80
  • CVE-2024-6001HigDec 16, 2024
    risk 0.53cvss 8.1epss 0.00

    An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.

  • CVE-2024-8007HigAug 21, 2024
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could…

  • CVE-2024-29072HigMay 28, 2024
    risk 0.53cvss 8.2epss 0.00

    A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected…

  • CVE-2024-30020HigMay 14, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Cryptographic Services Remote Code Execution Vulnerability

  • CVE-2024-2048HigMar 4, 2024
    risk 0.53cvss 8.1epss 0.00

    Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be…

  • CVE-2023-43017HigFeb 7, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

  • CVE-2023-48427HigDec 12, 2023
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to…

  • CVE-2023-38356HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38355HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38354HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38352HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38351HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-30729HigSep 6, 2023
    risk 0.53cvss 8.1epss 0.00

    Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

  • CVE-2023-38686CriAug 4, 2023
    risk 0.53cvss 9.3epss 0.00

    Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.…

  • CVE-2023-3615HigJul 17, 2023
    risk 0.53cvss 8.1epss 0.00

    Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

  • CVE-2023-31190HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.00

    DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS…

  • CVE-2023-35142HigJun 14, 2023
    risk 0.53cvss 8.1epss 0.01

    Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

  • CVE-2023-20881HigMay 19, 2023
    risk 0.53cvss 8.1epss 0.00

    Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This…

  • CVE-2022-45100HigFeb 1, 2023
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system.

  • CVE-2022-34469HigDec 22, 2022
    risk 0.53cvss 8.1epss 0.00

    When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user…