VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,509)

page 46 of 76
  • CVE-2014-8167MedNov 13, 2019
    risk 0.38cvss 5.9epss 0.01

    vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

  • CVE-2019-5538MedOct 28, 2019
    risk 0.38cvss 5.9epss 0.01

    Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data…

  • CVE-2019-5537MedOct 28, 2019
    risk 0.38cvss 5.9epss 0.01

    Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data…

  • CVE-2019-11674MedOct 22, 2019
    risk 0.38cvss 5.9epss 0.00

    Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.

  • CVE-2019-5506MedOct 9, 2019
    risk 0.38cvss 5.9epss 0.01

    Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.

  • CVE-2019-1948MedAug 21, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL certificate validation…

  • CVE-2019-1010206MedJul 23, 2019
    risk 0.38cvss 5.9epss 0.01

    OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.

  • CVE-2019-1940MedJul 17, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid X.509 certificate. The vulnerability is due to…

  • CVE-2019-4264MedMay 29, 2019
    risk 0.38cvss 5.9epss 0.01

    IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.

  • CVE-2019-11550MedMay 8, 2019
    risk 0.38cvss 5.9epss 0.01

    Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.

  • CVE-2019-10317MedApr 30, 2019
    risk 0.38cvss 5.9epss 0.01

    Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-10314MedApr 30, 2019
    risk 0.38cvss 5.9epss 0.01

    Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-1757MedMar 28, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation…

  • CVE-2019-6702MedMar 21, 2019
    risk 0.38cvss 5.9epss 0.01

    The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obsolete versions from 2016 or earlier.

  • CVE-2018-16187MedJan 9, 2019
    risk 0.38cvss 5.9epss 0.01

    The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive…

  • CVE-2018-16179MedJan 9, 2019
    risk 0.38cvss 5.9epss 0.01

    The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2018-0691MedNov 15, 2018
    risk 0.38cvss 5.9epss 0.01

    Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App…

  • CVE-2018-18568MedOct 24, 2018
    risk 0.38cvss 5.9epss 0.01

    Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

  • CVE-2018-18567MedOct 24, 2018
    risk 0.38cvss 5.9epss 0.01

    AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

  • CVE-2018-11087MedSep 14, 2018
    risk 0.38cvss 5.9epss 0.01

    Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.