VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 26 of 76
  • CVE-2020-3994HigOct 20, 2020
    risk 0.48cvss 7.4epss 0.01

    VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and…

  • CVE-2020-5913HigAug 26, 2020
    risk 0.48cvss 7.4epss 0.01

    In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SSL/TLS connections and may result in a man-in-the-middle…

  • CVE-2020-17366HigAug 5, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509…

  • CVE-2020-16164HigJul 30, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa"…

  • CVE-2020-5367HigJun 23, 2020
    risk 0.48cvss 7.4epss 0.01

    Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially…

  • CVE-2020-13163HigMay 19, 2020
    risk 0.48cvss 7.4epss 0.01

    em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.

  • CVE-2020-5864HigApr 23, 2020
    risk 0.48cvss 7.4epss 0.01

    In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

  • CVE-2019-11688HigMar 18, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Certificate Validation.

  • CVE-2020-8987HigMar 9, 2020
    risk 0.48cvss 7.4epss 0.01

    Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using…

  • CVE-2020-3155HigMar 4, 2020
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaboration endpoints if the products meet the conditions described…

  • CVE-2020-7904HigJan 30, 2020
    risk 0.48cvss 7.4epss 0.01

    In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

  • CVE-2020-5523HigJan 28, 2020
    risk 0.48cvss 7.4epss 0.01

    Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain…

  • CVE-2020-5522HigJan 27, 2020
    risk 0.48cvss 7.4epss 0.01

    The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2020-5521HigJan 27, 2020
    risk 0.48cvss 7.4epss 0.01

    The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2020-5520HigJan 27, 2020
    risk 0.48cvss 7.4epss 0.01

    The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2019-6032HigDec 26, 2019
    risk 0.48cvss 7.4epss 0.01

    The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2019-6687HigDec 23, 2019
    risk 0.48cvss 7.4epss 0.00

    On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.

  • CVE-2019-16209HigNov 8, 2019
    risk 0.48cvss 7.4epss 0.01

    A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections.

  • CVE-2019-3685HigNov 5, 2019
    risk 0.48cvss 7.4epss 0.01

    Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary

  • CVE-2019-14823HigOct 14, 2019
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be…