VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 20 of 76
  • CVE-2020-9040HigJun 8, 2020
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing…

  • CVE-2020-8172HigJun 8, 2020
    risk 0.49cvss 7.4epss 0.06

    TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

  • CVE-2020-1113HigMay 21, 2020
    risk 0.49cvss 7.5epss 0.07

    A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.

  • CVE-2020-11792HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.

  • CVE-2019-3762HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.01

    Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to…

  • CVE-2015-0294HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.02

    GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

  • CVE-2013-0264HigDec 30, 2019
    risk 0.49cvss 7.5epss 0.01

    An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.

  • CVE-2014-3495HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    duplicity 0.6.24 has improper verification of SSL certificates

  • CVE-2019-19270HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow…

  • CVE-2012-5518HigNov 25, 2019
    risk 0.49cvss 7.5epss 0.01

    vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

  • CVE-2014-2902HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

  • CVE-2014-2901HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

  • CVE-2012-6071HigNov 19, 2019
    risk 0.49cvss 7.5epss 0.01

    nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

  • CVE-2019-15042HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.

  • CVE-2019-11497HigSep 10, 2019
    risk 0.49cvss 7.5epss 0.01

    In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the certificate signature. It then accepted the invalid certificate and attempted to use it to establish future connections to the…

  • CVE-2016-10937HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

  • CVE-2019-10381HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-1006HigJul 15, 2019
    risk 0.49cvss 7.5epss 0.06

    An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.

  • CVE-2019-13050HigJun 29, 2019
    risk 0.49cvss 7.5epss 0.03

    Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent…

  • CVE-2019-0223HigApr 23, 2019
    risk 0.49cvss 7.4epss 0.06

    While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with…