VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 11 of 76
  • CVE-2023-35142HigJun 14, 2023
    risk 0.53cvss 8.1epss 0.01

    Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

  • CVE-2023-20881HigMay 19, 2023
    risk 0.53cvss 8.1epss 0.00

    Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This…

  • CVE-2022-45100HigFeb 1, 2023
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system.

  • CVE-2022-34469HigDec 22, 2022
    risk 0.53cvss 8.1epss 0.00

    When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user…

  • CVE-2022-41244HigSep 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-41243HigSep 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-36173HigSep 12, 2022
    risk 0.53cvss 8.1epss 0.01

    FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service.

  • CVE-2021-43766HigAug 25, 2022
    risk 0.53cvss 8.1epss 0.00

    Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL…

  • CVE-2022-1805HigJul 28, 2022
    risk 0.53cvss 8.1epss 0.01

    When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network.…

  • CVE-2022-32156HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation…

  • CVE-2022-32153HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2022-32152HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2021-21959HigFeb 4, 2022
    risk 0.53cvss 8.1epss 0.01

    A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.

  • CVE-2021-41028HigDec 16, 2021
    risk 0.53cvss 8.2epss 0.00

    A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and…

  • CVE-2021-3935HigNov 22, 2021
    risk 0.53cvss 8.1epss 0.01

    When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.

  • CVE-2021-23167HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.00

    Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3); 8.40 versions prior to 8.40.2063…

  • CVE-2021-32581HigAug 5, 2021
    risk 0.53cvss 8.1epss 0.01

    Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.

  • CVE-2021-3460HigApr 13, 2021
    risk 0.53cvss 8.1epss 0.01

    The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.

  • CVE-2019-16558HigDec 17, 2019
    risk 0.53cvss 8.2epss 0.01

    Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.

  • CVE-2016-10931HigAug 26, 2019
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.