VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 21 of 80
  • CVE-2021-27400HigApr 22, 2021
    risk 0.49cvss 7.5epss 0.01

    HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1

  • CVE-2021-21373HigMar 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS URL…

  • CVE-2021-1277HigJan 20, 2021
    risk 0.49cvss 7.5epss 0.00

    Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate…

  • CVE-2021-1276HigJan 20, 2021
    risk 0.49cvss 7.5epss 0.00

    Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate…

  • CVE-2020-8286HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.05

    curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

  • CVE-2020-28362HigNov 18, 2020
    risk 0.49cvss 7.5epss 0.04

    Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.

  • CVE-2019-17007HigOct 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

  • CVE-2020-24560HigSep 24, 2020
    risk 0.49cvss 7.5epss 0.02

    An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of…

  • CVE-2020-15604HigSep 24, 2020
    risk 0.49cvss 7.5epss 0.02

    An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of…

  • CVE-2020-16162HigJul 30, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass intended access restrictions by using…

  • CVE-2020-9040HigJun 8, 2020
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing…

  • CVE-2020-8172HigJun 8, 2020
    risk 0.49cvss 7.4epss 0.06

    TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

  • CVE-2020-11792HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.

  • CVE-2019-3762HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.01

    Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to…

  • CVE-2015-0294HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.02

    GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

  • CVE-2013-0264HigDec 30, 2019
    risk 0.49cvss 7.5epss 0.01

    An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.

  • CVE-2014-3495HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    duplicity 0.6.24 has improper verification of SSL certificates

  • CVE-2019-19270HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow…

  • CVE-2012-5518HigNov 25, 2019
    risk 0.49cvss 7.5epss 0.01

    vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

  • CVE-2014-2902HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.