VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,509)

page 44 of 76
  • CVE-2022-33682MedSep 23, 2022
    risk 0.38cvss 5.9epss 0.01

    TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication connections vulnerable to…

  • CVE-2022-33681MedSep 23, 2022
    risk 0.38cvss 5.9epss 0.01

    Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connections from the Pulsar Java Client to the Pulsar Broker/Proxy and connections from the Pulsar Proxy to the Pulsar Broker are…

  • CVE-2021-43767MedAug 25, 2022
    risk 0.38cvss 5.9epss 0.00

    Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses…

  • CVE-2022-20081MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID:…

  • CVE-2022-0123MedMar 28, 2022
    risk 0.38cvss 5.9epss 0.00

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these…

  • CVE-2021-42017MedMar 8, 2022
    risk 0.38cvss 5.9epss 0.00

    A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M969, RUGGEDCOM M969F, RUGGEDCOM RMC30, RUGGEDCOM RMC8388 V4.X, RUGGEDCOM RMC8388 V5.X,…

  • CVE-2022-24320MedFeb 9, 2022
    risk 0.38cvss 5.9epss 0.01

    A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All…

  • CVE-2022-24319MedFeb 9, 2022
    risk 0.38cvss 5.9epss 0.01

    A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All…

  • CVE-2020-4496MedDec 13, 2021
    risk 0.38cvss 5.9epss 0.01

    The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

  • CVE-2021-40713MedSep 27, 2021
    risk 0.38cvss 5.9epss 0.01

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest…

  • CVE-2021-39365MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39361MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39360MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-39358MedAug 22, 2021
    risk 0.38cvss 5.9epss 0.01

    In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

  • CVE-2021-21571MedJun 24, 2021
    risk 0.38cvss 5.9epss 0.01

    Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a…

  • CVE-2021-20732MedJun 9, 2021
    risk 0.38cvss 5.9epss 0.00

    The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on encrypted communication via a crafted certificate.

  • CVE-2021-29495MedMay 7, 2021
    risk 0.38cvss 5.9epss 0.00

    Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set "verifyMode = CVerifyPeer"…

  • CVE-2021-22189MedMar 4, 2021
    risk 0.38cvss 5.9epss 0.01

    Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

  • CVE-2021-27189MedFeb 23, 2021
    risk 0.38cvss 5.9epss 0.01

    The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.

  • CVE-2020-24393MedFeb 19, 2021
    risk 0.38cvss 5.9epss 0.01

    TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.