CWE-295
Improper Certificate Validation
Description
The product does not validate, or incorrectly validates, a certificate.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-459 · CAPEC-475
CVEs mapped to this weakness (1,505)
page 17 of 76| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45234 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER decoder, reaching a point in… | ||
| CVE-2024-41264 | Hig | 0.49 | 7.5 | 0.00 | Aug 1, 2024 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. | ||
| CVE-2024-41255 | Hig | 0.49 | 7.5 | 0.00 | Jul 31, 2024 | filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go. | ||
| CVE-2024-31872 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316. | ||
| CVE-2024-31871 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306. | ||
| CVE-2024-27323 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2024 | PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this… | ||
| CVE-2023-40104 | Hig | 0.49 | 7.5 | 0.00 | Feb 15, 2024 | In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-32330 | Hig | 0.49 | 7.5 | 0.01 | Feb 7, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977. | ||
| CVE-2023-5594 | Hig | 0.49 | 7.5 | 0.00 | Dec 21, 2023 | Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted. | ||
| CVE-2009-4123 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2023 | The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation. | ||
| CVE-2023-49247 | Hig | 0.49 | 7.5 | 0.00 | Dec 6, 2023 | Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-5909 | Hig | 0.49 | 7.5 | 0.00 | Nov 30, 2023 | KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect. | ||
| CVE-2023-4499 | Hig | 0.49 | 7.5 | 0.01 | Oct 13, 2023 | A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability. | ||
| CVE-2023-4801 | Hig | 0.49 | 7.5 | 0.00 | Sep 13, 2023 | An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All… | ||
| CVE-2023-21265 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2023 | In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-30222 | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2023 | An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping. | ||
| CVE-2022-45458 | Hig | 0.49 | 7.5 | 0.00 | May 18, 2023 | Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984. | ||
| CVE-2022-45457 | Hig | 0.49 | 7.5 | 0.00 | May 18, 2023 | Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984. | ||
| CVE-2023-22642 | Hig | 0.49 | 7.5 | 0.00 | Apr 11, 2023 | An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between… | ||
| CVE-2023-0464 | Hig | 0.49 | 7.5 | 0.04 | Mar 22, 2023 | A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that… |
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER decoder, reaching a point in…
- risk 0.49cvss 7.5epss 0.00
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
- risk 0.49cvss 7.5epss 0.00
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.
- risk 0.49cvss 7.5epss 0.00
PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this…
- risk 0.49cvss 7.5epss 0.00
In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.
- risk 0.49cvss 7.5epss 0.00
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
- risk 0.49cvss 7.5epss 0.01
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
- risk 0.49cvss 7.5epss 0.00
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
- risk 0.49cvss 7.5epss 0.01
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.
- risk 0.49cvss 7.5epss 0.00
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All…
- risk 0.49cvss 7.5epss 0.00
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.49cvss 7.5epss 0.01
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.
- risk 0.49cvss 7.5epss 0.00
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.
- risk 0.49cvss 7.5epss 0.00
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between…
- risk 0.49cvss 7.5epss 0.04
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that…