VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 38 of 80
  • CVE-2023-0430MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird <…

  • CVE-2023-1664MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated…

  • CVE-2023-23901MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdrop on or alter the communication sent to…

  • CVE-2023-30516MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation…

  • CVE-2023-28093MedApr 10, 2023
    risk 0.42cvss 6.5epss 0.01

    A user with a compromised configuration can start an unsigned binary as a service.

  • CVE-2022-34404MedFeb 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.

  • CVE-2022-45419MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted.…

  • CVE-2022-22747MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2022-1834MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email message with the attacker's digital…

  • CVE-2022-1632MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.00

    An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting…

  • CVE-2021-22131MedJul 18, 2022
    risk 0.42cvss 6.4epss 0.00

    A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 and below, Fortinet FortiTokenWinApp version 4.0.3 and below allows attacker to retrieve information disclosed via…

  • CVE-2022-32210MedJul 14, 2022
    risk 0.42cvss 6.5epss 0.00

    `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are…

  • CVE-2022-27782HigJun 2, 2022
    risk 0.42cvss 7.5epss 0.03

    libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However,…

  • CVE-2022-24901HigMay 4, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks…

  • CVE-2022-25243MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in…

  • CVE-2022-22156MedJan 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and confidentiality of…

  • CVE-2021-36756MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.00

    CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.

  • CVE-2021-3761HigSep 9, 2021
    risk 0.42cvss 7.5epss 0.01

    Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a…

  • CVE-2020-36478HigAug 23, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way,…

  • CVE-2020-15732MedJun 22, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to…