VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,509)

page 45 of 76
  • CVE-2020-24392MedFeb 19, 2021
    risk 0.38cvss 5.9epss 0.01

    In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).

  • CVE-2020-5812MedFeb 6, 2021
    risk 0.38cvss 5.9epss 0.01

    Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

  • CVE-2020-11617MedAug 31, 2020
    risk 0.38cvss 5.9epss 0.00

    The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.

  • CVE-2020-24661MedAug 26, 2020
    risk 0.38cvss 5.9epss 0.01

    GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the…

  • CVE-2020-15498MedAug 26, 2020
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files.

  • CVE-2020-15526MedJul 9, 2020
    risk 0.38cvss 5.9epss 0.01

    In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications. These TLS…

  • CVE-2020-15047MedJun 25, 2020
    risk 0.38cvss 5.9epss 0.01

    MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.

  • CVE-2020-14981MedJun 22, 2020
    risk 0.38cvss 5.9epss 0.01

    The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.

  • CVE-2020-14980MedJun 22, 2020
    risk 0.38cvss 5.9epss 0.01

    The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.

  • CVE-2019-16252MedJun 12, 2020
    risk 0.38cvss 5.9epss 0.00

    Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.

  • CVE-2020-13245MedMay 28, 2020
    risk 0.38cvss 5.9epss 0.01

    Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.

  • CVE-2020-13615MedMay 26, 2020
    risk 0.38cvss 5.9epss 0.01

    lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.

  • CVE-2020-11806MedApr 23, 2020
    risk 0.38cvss 5.9epss 0.00

    In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.

  • CVE-2020-6175MedMar 16, 2020
    risk 0.38cvss 5.9epss 0.01

    Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.

  • CVE-2020-5526MedJan 31, 2020
    risk 0.38cvss 5.9epss 0.01

    The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2020-3940MedJan 17, 2020
    risk 0.38cvss 5.9epss 0.01

    VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.

  • CVE-2012-1316MedJan 15, 2020
    risk 0.38cvss 5.9epss 0.01

    Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks

  • CVE-2014-0161MedJan 2, 2020
    risk 0.38cvss 5.9epss 0.00

    ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote…

  • CVE-2014-0104MedJan 2, 2020
    risk 0.38cvss 5.9epss 0.01

    In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

  • CVE-2019-11554MedDec 6, 2019
    risk 0.38cvss 5.9epss 0.00

    The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.