VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 19 of 80
  • CVE-2023-49247HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-5909HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.00

    KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

  • CVE-2023-4499HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

  • CVE-2023-4801HigSep 13, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All…

  • CVE-2023-21265HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-30222HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.

  • CVE-2022-45458HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.

  • CVE-2022-45457HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2023-22642HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between…

  • CVE-2023-0464HigMar 22, 2023
    risk 0.49cvss 7.5epss 0.04

    A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that…

  • CVE-2023-23131HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.

  • CVE-2022-45197HigDec 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

  • CVE-2022-20960HigNov 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that…

  • CVE-2022-26305HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to…

  • CVE-2021-29755HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.

  • CVE-2020-16093HigJul 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

  • CVE-2022-31083HigJun 17, 2022
    risk 0.49cvss 8.6epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be…

  • CVE-2020-26184HigJun 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.

  • CVE-2022-27536HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.

  • CVE-2022-22549HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials.