VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 32 of 80
  • CVE-2025-54424HigAug 1, 2025
    risk 0.46cvss 8.1epss 0.01

    1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, the HTTPS protocol used for communication between the Core and Agent endpoints has incomplete certificate verification during…

  • CVE-2024-45205HigDec 4, 2024
    risk 0.46cvss 7.1epss 0.00

    An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App…

  • CVE-2024-7206HigOct 8, 2024
    risk 0.46cvss —epss 0.00

    SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware

  • CVE-2024-37311HigAug 23, 2024
    risk 0.46cvss 8.2epss 0.00

    Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is…

  • CVE-2023-23690HigJan 19, 2023
    risk 0.46cvss 7.0epss 0.00

    Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle…

  • CVE-2022-46153HigDec 8, 2022
    risk 0.46cvss 8.1epss 0.01

    Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS connections. A router configured with a not well-formatted TLSOption is exposed with an empty TLSOption. For instance, a route secured…

  • CVE-2022-33684HigNov 4, 2022
    risk 0.46cvss 8.1epss 0.01

    The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. This vulnerability allows an attacker to perform a man in the middle attack and…

  • CVE-2022-36881HigJul 27, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.

  • CVE-2022-0759HigMar 25, 2022
    risk 0.46cvss 8.1epss 0.01

    A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate…

  • CVE-2021-21559HigJun 8, 2021
    risk 0.46cvss 7.1epss 0.00

    Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in the client (NetWorker Management Console) components which uses SSL encrypted connection in order to communicate with the application server.…

  • CVE-2021-27098HigMar 5, 2021
    risk 0.46cvss 8.1epss 0.01

    In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible issuance of an X.509 certificate with a URI SAN for a SPIFFE ID that the agent is…

  • CVE-2020-8156HigMay 12, 2020
    risk 0.46cvss 7.0epss 0.01

    A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.

  • CVE-2019-16561HigDec 17, 2019
    risk 0.46cvss 7.1epss 0.01

    Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.

  • CVE-2019-10446HigOct 16, 2019
    risk 0.46cvss 8.2epss 0.01

    Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-3890HigAug 1, 2019
    risk 0.46cvss 8.1epss 0.01

    It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.

  • CVE-2018-1000500HigJun 26, 2018
    risk 0.46cvss 8.1epss 0.02

    Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-…

  • CVE-2018-6219MedMar 15, 2018
    risk 0.46cvss 6.5epss 0.04

    An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.

  • CVE-2018-1000096HigMar 13, 2018
    risk 0.46cvss 8.1epss 0.01

    brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to…

  • CVE-2017-2667HigMar 12, 2018
    risk 0.46cvss 8.1epss 0.01

    Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

  • CVE-2015-2318HigJan 8, 2018
    risk 0.46cvss 8.1epss 0.02

    The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.