VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 15 of 80
  • CVE-2026-41859HigJun 4, 2026
    risk 0.51cvss 7.8epss 0.00

    A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director…

  • CVE-2025-34235HigSep 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client to skip SSL/TLS certificate validation.…

  • CVE-2024-4762HigDec 16, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.

  • CVE-2024-38642HigSep 6, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following…

  • CVE-2024-6472HigAug 5, 2024
    risk 0.51cvss 7.8epss 0.00

    Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by…

  • CVE-2024-0042HigMay 7, 2024
    risk 0.51cvss 7.8epss 0.00

    In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-6043HigJan 19, 2024
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges.

  • CVE-2020-12614HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is…

  • CVE-2023-21358HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-32748HigJan 30, 2023
    risk 0.51cvss 7.9epss 0.00

    A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration…

  • CVE-2022-41747HigOct 10, 2022
    risk 0.51cvss 7.8epss 0.00

    An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with system service privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2022-29908HigSep 19, 2022
    risk 0.51cvss 7.8epss 0.00

    The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.

  • CVE-2022-21836HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Certificate Spoofing Vulnerability

  • CVE-2021-3162HigJan 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.

  • CVE-2020-8289HigDec 27, 2020
    risk 0.51cvss 7.8epss 0.05

    Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client…

  • CVE-2018-10408HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the…

  • CVE-2018-10405HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is…

  • CVE-2018-10404HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party…

  • CVE-2018-10403HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is…

  • CVE-2026-86474HigSep 16, 2026
    risk 0.50cvss —epss 0.00

    The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.