VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 18 of 80
  • CVE-2025-12943HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute…

  • CVE-2025-54470HigOct 30, 2025
    risk 0.49cvss 8.6epss 0.00

    This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server. In affected versions, NeuVector does not enforce TLS certificate…

  • CVE-2025-59353HigSep 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Manager’s Certificate gRPC…

  • CVE-2024-10444HigMar 19, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2025-0501HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.

  • CVE-2025-0500HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.

  • CVE-2024-48865HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system. We have already fixed the vulnerability…

  • CVE-2023-51634HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30 routers. Authentication is not required to…

  • CVE-2024-8287HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take…

  • CVE-2024-41996HigAug 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause…

  • CVE-2024-45234HigAug 24, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER decoder, reaching a point in…

  • CVE-2024-41264HigAug 1, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

  • CVE-2024-41255HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.00

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.

  • CVE-2024-31872HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.

  • CVE-2024-31871HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.

  • CVE-2024-27323HigApr 1, 2024
    risk 0.49cvss 7.5epss 0.00

    PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this…

  • CVE-2023-40104HigFeb 15, 2024
    risk 0.49cvss 7.5epss 0.00

    In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-32330HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.

  • CVE-2023-5594HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

  • CVE-2009-4123HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.