CWE-295
Improper Certificate Validation
Description
The product does not validate, or incorrectly validates, a certificate.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-459 · CAPEC-475
CVEs mapped to this weakness (1,509)
page 45 of 76| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24392 | Med | 0.38 | 5.9 | 0.01 | Feb 19, 2021 | In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused). | ||
| CVE-2020-5812 | Med | 0.38 | 5.9 | 0.01 | Feb 6, 2021 | Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. | ||
| CVE-2020-11617 | Med | 0.38 | 5.9 | 0.00 | Aug 31, 2020 | The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client. | ||
| CVE-2020-24661 | Med | 0.38 | 5.9 | 0.01 | Aug 26, 2020 | GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the… | ||
| CVE-2020-15498 | Med | 0.38 | 5.9 | 0.00 | Aug 26, 2020 | An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files. | ||
| CVE-2020-15526 | Med | 0.38 | 5.9 | 0.01 | Jul 9, 2020 | In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications. These TLS… | ||
| CVE-2020-15047 | Med | 0.38 | 5.9 | 0.01 | Jun 25, 2020 | MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers. | ||
| CVE-2020-14981 | Med | 0.38 | 5.9 | 0.01 | Jun 22, 2020 | The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation. | ||
| CVE-2020-14980 | Med | 0.38 | 5.9 | 0.01 | Jun 22, 2020 | The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation. | ||
| CVE-2019-16252 | Med | 0.38 | 5.9 | 0.00 | Jun 12, 2020 | Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data. | ||
| CVE-2020-13245 | Med | 0.38 | 5.9 | 0.01 | May 28, 2020 | Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P. | ||
| CVE-2020-13615 | Med | 0.38 | 5.9 | 0.01 | May 26, 2020 | lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates. | ||
| CVE-2020-11806 | Med | 0.38 | 5.9 | 0.00 | Apr 23, 2020 | In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server. | ||
| CVE-2020-6175 | Med | 0.38 | 5.9 | 0.01 | Mar 16, 2020 | Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. | ||
| CVE-2020-5526 | Med | 0.38 | 5.9 | 0.01 | Jan 31, 2020 | The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | ||
| CVE-2020-3940 | Med | 0.38 | 5.9 | 0.01 | Jan 17, 2020 | VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability. | ||
| CVE-2012-1316 | Med | 0.38 | 5.9 | 0.01 | Jan 15, 2020 | Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks | ||
| CVE-2014-0161 | Med | 0.38 | 5.9 | 0.00 | Jan 2, 2020 | ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote… | ||
| CVE-2014-0104 | Med | 0.38 | 5.9 | 0.01 | Jan 2, 2020 | In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates. | ||
| CVE-2019-11554 | Med | 0.38 | 5.9 | 0.00 | Dec 6, 2019 | The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service. |
- risk 0.38cvss 5.9epss 0.01
In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).
- risk 0.38cvss 5.9epss 0.01
Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
- risk 0.38cvss 5.9epss 0.00
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.
- risk 0.38cvss 5.9epss 0.01
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the…
- risk 0.38cvss 5.9epss 0.00
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files.
- risk 0.38cvss 5.9epss 0.01
In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications. These TLS…
- risk 0.38cvss 5.9epss 0.01
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
- risk 0.38cvss 5.9epss 0.01
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
- risk 0.38cvss 5.9epss 0.01
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
- risk 0.38cvss 5.9epss 0.00
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.
- risk 0.38cvss 5.9epss 0.01
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.
- risk 0.38cvss 5.9epss 0.01
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
- risk 0.38cvss 5.9epss 0.00
In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.
- risk 0.38cvss 5.9epss 0.01
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
- risk 0.38cvss 5.9epss 0.01
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- risk 0.38cvss 5.9epss 0.01
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
- risk 0.38cvss 5.9epss 0.01
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
- risk 0.38cvss 5.9epss 0.00
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote…
- risk 0.38cvss 5.9epss 0.01
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
- risk 0.38cvss 5.9epss 0.00
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.