VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 37 of 80
  • CVE-2025-59347MedSep 17, 2025
    risk 0.42cvss 6.5epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable the verification. A Manager processes…

  • CVE-2025-2028MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

  • CVE-2025-35983MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for…

  • CVE-2025-48802MedJul 8, 2025
    risk 0.42cvss 6.5epss 0.01

    Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-39205MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

  • CVE-2025-24471MedJun 10, 2025
    risk 0.42cvss 6.5epss 0.00

    An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

  • CVE-2025-4947MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

  • CVE-2024-45641MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.

  • CVE-2023-33861MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.

  • CVE-2025-37730MedMay 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode => full was set.

  • CVE-2025-27820HigApr 24, 2025
    risk 0.42cvss 7.5epss 0.01

    A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

  • CVE-2025-23118MedMar 1, 2025
    risk 0.42cvss 6.4epss 0.00

    An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.

  • CVE-2024-23970MedJan 31, 2025
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST…

  • CVE-2024-23928MedJan 31, 2025
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the telematics…

  • CVE-2024-32865MedAug 1, 2024
    risk 0.42cvss 6.4epss 0.00

    Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

  • CVE-2024-39698HigJul 9, 2024
    risk 0.42cvss 7.5epss 0.00

    electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` implements the signature validation routine for Electron applications on Windows. Because of the surrounding shell, a first pass by…

  • CVE-2023-50356MedJan 31, 2024
    risk 0.42cvss 6.5epss 0.00

    SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.

  • CVE-2023-33295MedJan 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.

  • CVE-2023-38325HigJul 14, 2023
    risk 0.42cvss 7.5epss 0.01

    The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

  • CVE-2023-0547MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird versions from 68 to 102.9.1 were affected by this bug. This vulnerability affects Thunderbird < 102.10.