VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,509)

page 35 of 76
  • CVE-2025-37730MedMay 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode => full was set.

  • CVE-2025-27820HigApr 24, 2025
    risk 0.42cvss 7.5epss 0.01

    A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

  • CVE-2025-23118MedMar 1, 2025
    risk 0.42cvss 6.4epss 0.00

    An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.

  • CVE-2024-23970MedJan 31, 2025
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST…

  • CVE-2024-23928MedJan 31, 2025
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the telematics…

  • CVE-2024-32865MedAug 1, 2024
    risk 0.42cvss 6.4epss 0.00

    Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

  • CVE-2024-39698HigJul 9, 2024
    risk 0.42cvss 7.5epss 0.00

    electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` implements the signature validation routine for Electron applications on Windows. Because of the surrounding shell, a first pass by…

  • CVE-2023-50356MedJan 31, 2024
    risk 0.42cvss 6.5epss 0.00

    SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.

  • CVE-2023-33295MedJan 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.

  • CVE-2023-38325HigJul 14, 2023
    risk 0.42cvss 7.5epss 0.01

    The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

  • CVE-2023-0547MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.

  • CVE-2023-0430MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird <…

  • CVE-2023-1664MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated…

  • CVE-2023-23901MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdrop on or alter the communication sent to…

  • CVE-2023-30516MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation…

  • CVE-2023-28093MedApr 10, 2023
    risk 0.42cvss 6.5epss 0.01

    A user with a compromised configuration can start an unsigned binary as a service.

  • CVE-2022-34404MedFeb 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.

  • CVE-2022-45419MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted.…

  • CVE-2022-22747MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2022-1834MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email message with the attacker's digital…