VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 2 of 76
  • CVE-2023-40256CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.00

    A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting…

  • CVE-2022-35898CriMay 1, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

  • CVE-2022-47758CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

  • CVE-2023-26463CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.02

    strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is…

  • CVE-2022-45597CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion…

  • CVE-2022-42813CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary…

  • CVE-2022-34831CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an…

  • CVE-2022-32563CriJun 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509…

  • CVE-2022-26493CriJun 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML…

  • CVE-2021-29656CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.

  • CVE-2022-22885CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.

  • CVE-2021-40855CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.

  • CVE-2021-33907CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.03

    The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

  • CVE-2020-28907CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.03

    Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

  • CVE-2021-1471CriMar 24, 2021
    risk 0.64cvss 9.9epss 0.01

    Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept…

  • CVE-2021-3406CriFeb 25, 2021
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.

  • CVE-2019-8531CriOct 27, 2020
    risk 0.64cvss 9.8epss 0.01

    A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server…

  • CVE-2020-24715CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.01

    The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.

  • CVE-2019-18847CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

  • CVE-2020-12637CriMay 9, 2020
    risk 0.64cvss 9.8epss 0.01

    Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.