VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,509)

page 37 of 76
  • CVE-2020-27589HigNov 6, 2020
    risk 0.42cvss 7.5epss 0.01

    Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.

  • CVE-2020-12421MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.02

    When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability…

  • CVE-2019-20894HigJul 2, 2020
    risk 0.42cvss 7.5epss 0.02

    Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.

  • CVE-2017-18909HigJun 19, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

  • CVE-2020-4320MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.

  • CVE-2020-13645MedMay 28, 2020
    risk 0.42cvss 6.5epss 0.02

    In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the…

  • CVE-2019-19101MedApr 29, 2020
    risk 0.42cvss 6.5epss 0.01

    A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade…

  • CVE-2020-7922MedApr 9, 2020
    risk 0.42cvss 6.4epss 0.01

    X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their…

  • CVE-2020-7919HigMar 16, 2020
    risk 0.42cvss 7.5epss 0.03

    Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

  • CVE-2020-7942MedFeb 19, 2020
    risk 0.42cvss 6.5epss 0.01

    Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog…

  • CVE-2011-2669MedJan 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

  • CVE-2020-1929HigJan 15, 2020
    risk 0.42cvss 7.5epss 0.01

    The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally…

  • CVE-2019-19271HigNov 26, 2019
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and can allow clients whose certificates…

  • CVE-2014-7143HigNov 12, 2019
    risk 0.42cvss 7.5epss 0.03

    Python Twisted 14.0 trustRoot is not respected in HTTP client

  • CVE-2019-10444MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.

  • CVE-2019-3751MedSep 3, 2019
    risk 0.42cvss 6.4epss 0.01

    Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted…

  • CVE-2019-5280MedAug 13, 2019
    risk 0.42cvss 6.5epss 0.00

    The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can perform man-in-the-middle attacks, leading to the affected…

  • CVE-2019-10382MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2017-18479MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.00

    In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).

  • CVE-2019-3875MedJun 12, 2019
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The…