VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 4 of 76
  • CVE-2025-7395CriJul 18, 2025
    risk 0.60cvss epss 0.00

    A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certificate issued by a trusted…

  • CVE-2017-3563HigApr 24, 2017
    risk 0.60cvss 8.8epss 0.01

    Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure…

  • CVE-2026-49457CriAug 14, 2026
    risk 0.59cvss 9.1epss 0.00

    erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared…

  • CVE-2026-71290CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the…

  • CVE-2026-45388CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).

  • CVE-2025-70043CriFeb 23, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options

  • CVE-2025-65830CriDec 10, 2025
    risk 0.59cvss 9.1epss 0.00

    Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can decrypt the TLS traffic, inspect its contents, and modify the requests in transit. This may result in a total compromise of the…

  • CVE-2025-56231CriNov 5, 2025
    risk 0.59cvss 9.1epss 0.00

    Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

  • CVE-2025-55109CriSep 16, 2025
    risk 0.59cvss 9.0epss 0.00

    An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed…

  • CVE-2025-7390CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.00

    A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

  • CVE-2025-23114CriFeb 5, 2025
    risk 0.59cvss 9.0epss 0.01

    A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.

  • CVE-2023-49312CriNov 26, 2023
    risk 0.59cvss 9.1epss 0.01

    Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.

  • CVE-2022-31733CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are…

  • CVE-2022-42979HigJan 6, 2023
    risk 0.59cvss 8.8epss 0.24

    Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link.

  • CVE-2022-43705CriNov 27, 2022
    risk 0.59cvss 9.1epss 0.00

    In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).

  • CVE-2022-20813CriJul 6, 2022
    risk 0.59cvss 9.0epss 0.01

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected…

  • CVE-2014-8164CriJul 6, 2022
    risk 0.59cvss 9.1epss 0.01

    A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

  • CVE-2021-45490CriMar 28, 2022
    risk 0.59cvss 9.1epss 0.01

    The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.

  • CVE-2021-43882CriDec 15, 2021
    risk 0.59cvss 9.0epss 0.02

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-23155CriNov 18, 2021
    risk 0.59cvss 9.0epss 0.00

    Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior…