CWE-295
Improper Certificate Validation
Description
The product does not validate, or incorrectly validates, a certificate.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-459 · CAPEC-475
CVEs mapped to this weakness (1,595)
page 21 of 80| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27400 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2021 | HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1 | ||
| CVE-2021-21373 | Hig | 0.49 | 7.5 | 0.01 | Mar 26, 2021 | Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS URL… | ||
| CVE-2021-1277 | Hig | 0.49 | 7.5 | 0.00 | Jan 20, 2021 | Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate… | ||
| CVE-2021-1276 | Hig | 0.49 | 7.5 | 0.00 | Jan 20, 2021 | Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate… | ||
| CVE-2020-8286 | Hig | 0.49 | 7.5 | 0.05 | Dec 14, 2020 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | ||
| CVE-2020-28362 | Hig | 0.49 | 7.5 | 0.04 | Nov 18, 2020 | Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. | ||
| CVE-2019-17007 | Hig | 0.49 | 7.5 | 0.01 | Oct 22, 2020 | In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. | ||
| CVE-2020-24560 | Hig | 0.49 | 7.5 | 0.02 | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of… | ||
| CVE-2020-15604 | Hig | 0.49 | 7.5 | 0.02 | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of… | ||
| CVE-2020-16162 | Hig | 0.49 | 7.5 | 0.01 | Jul 30, 2020 | An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass intended access restrictions by using… | ||
| CVE-2020-9040 | Hig | 0.49 | 7.5 | 0.01 | Jun 8, 2020 | Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing… | ||
| CVE-2020-8172 | Hig | 0.49 | 7.4 | 0.06 | Jun 8, 2020 | TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. | ||
| CVE-2020-11792 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2020 | NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure. | ||
| CVE-2019-3762 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2020 | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to… | ||
| CVE-2015-0294 | Hig | 0.49 | 7.5 | 0.02 | Jan 27, 2020 | GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate. | ||
| CVE-2013-0264 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2019 | An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it. | ||
| CVE-2014-3495 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2019 | duplicity 0.6.24 has improper verification of SSL certificates | ||
| CVE-2019-19270 | Hig | 0.49 | 7.5 | 0.01 | Nov 26, 2019 | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow… | ||
| CVE-2012-5518 | Hig | 0.49 | 7.5 | 0.01 | Nov 25, 2019 | vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate) | ||
| CVE-2014-2902 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2019 | wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates. |
- risk 0.49cvss 7.5epss 0.01
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
- risk 0.49cvss 7.5epss 0.01
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS URL…
- risk 0.49cvss 7.5epss 0.00
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate…
- risk 0.49cvss 7.5epss 0.00
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate…
- risk 0.49cvss 7.5epss 0.05
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
- risk 0.49cvss 7.5epss 0.04
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
- risk 0.49cvss 7.5epss 0.01
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.02
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of…
- risk 0.49cvss 7.5epss 0.02
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass intended access restrictions by using…
- risk 0.49cvss 7.5epss 0.01
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing…
- risk 0.49cvss 7.4epss 0.06
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
- risk 0.49cvss 7.5epss 0.01
NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.
- risk 0.49cvss 7.5epss 0.01
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to…
- risk 0.49cvss 7.5epss 0.02
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
- risk 0.49cvss 7.5epss 0.01
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
- risk 0.49cvss 7.5epss 0.01
duplicity 0.6.24 has improper verification of SSL certificates
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow…
- risk 0.49cvss 7.5epss 0.01
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
- risk 0.49cvss 7.5epss 0.01
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.