VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 17 of 76
  • CVE-2024-45234HigAug 24, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER decoder, reaching a point in…

  • CVE-2024-41264HigAug 1, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

  • CVE-2024-41255HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.00

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.

  • CVE-2024-31872HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.

  • CVE-2024-31871HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.

  • CVE-2024-27323HigApr 1, 2024
    risk 0.49cvss 7.5epss 0.00

    PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this…

  • CVE-2023-40104HigFeb 15, 2024
    risk 0.49cvss 7.5epss 0.00

    In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-32330HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.

  • CVE-2023-5594HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

  • CVE-2009-4123HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.

  • CVE-2023-49247HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-5909HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.00

    KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

  • CVE-2023-4499HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

  • CVE-2023-4801HigSep 13, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All…

  • CVE-2023-21265HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-30222HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.

  • CVE-2022-45458HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.

  • CVE-2022-45457HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2023-22642HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between…

  • CVE-2023-0464HigMar 22, 2023
    risk 0.49cvss 7.5epss 0.04

    A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that…