CWE-295
Improper Certificate Validation
Description
The product does not validate, or incorrectly validates, a certificate.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-459 · CAPEC-475
CVEs mapped to this weakness (1,595)
page 5 of 80| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49312 | Cri | 0.59 | 9.1 | 0.01 | Nov 26, 2023 | Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address. | ||
| CVE-2022-31733 | Cri | 0.59 | 9.1 | 0.00 | Feb 3, 2023 | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are… | ||
| CVE-2022-42979 | Hig | 0.59 | 8.8 | 0.24 | Jan 6, 2023 | Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link. | ||
| CVE-2022-43705 | Cri | 0.59 | 9.1 | 0.00 | Nov 27, 2022 | In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016). | ||
| CVE-2022-20813 | Cri | 0.59 | 9.0 | 0.01 | Jul 6, 2022 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected… | ||
| CVE-2014-8164 | Cri | 0.59 | 9.1 | 0.01 | Jul 6, 2022 | A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x. | ||
| CVE-2021-45490 | — | Cri | 0.59 | 9.1 | 0.01 | Mar 28, 2022 | The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation. | |
| CVE-2021-43882 | Cri | 0.59 | 9.0 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-23155 | Cri | 0.59 | 9.0 | 0.00 | Nov 18, 2021 | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior… | ||
| CVE-2021-33695 | Cri | 0.59 | 9.1 | 0.01 | Sep 15, 2021 | Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate. | ||
| CVE-2020-29663 | Cri | 0.59 | 9.1 | 0.02 | Dec 15, 2020 | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3. | ||
| CVE-2020-9868 | Cri | 0.59 | 9.1 | 0.01 | Oct 22, 2020 | A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been… | ||
| CVE-2020-16163 | Cri | 0.59 | 9.1 | 0.01 | Jul 30, 2020 | An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass intended access restrictions, or to trigger denial of service to traffic… | ||
| CVE-2020-11050 | Cri | 0.59 | 9.0 | 0.01 | May 7, 2020 | In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0. | ||
| CVE-2020-11580 | Cri | 0.59 | 9.1 | 0.01 | Apr 6, 2020 | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate. | ||
| CVE-2019-17560 | Cri | 0.59 | 9.1 | 0.02 | Mar 30, 2020 | The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and… | ||
| CVE-2017-17945 | Cri | 0.59 | 9.1 | 0.01 | Jun 24, 2019 | The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation. | ||
| CVE-2017-17944 | Cri | 0.59 | 9.1 | 0.01 | Jun 20, 2019 | The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation. | ||
| CVE-2018-5926 | Cri | 0.59 | 9.1 | 0.01 | Mar 27, 2019 | A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier. | ||
| CVE-2019-8351 | Cri | 0.59 | 9.1 | 0.01 | Mar 21, 2019 | Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate. |
- risk 0.59cvss 9.1epss 0.01
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.
- risk 0.59cvss 9.1epss 0.00
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are…
- risk 0.59cvss 8.8epss 0.24
Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link.
- risk 0.59cvss 9.1epss 0.00
In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).
- risk 0.59cvss 9.0epss 0.01
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected…
- risk 0.59cvss 9.1epss 0.01
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.
- risk 0.59cvss 9.1epss 0.01
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.
- risk 0.59cvss 9.0epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.00
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior…
- risk 0.59cvss 9.1epss 0.01
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
- risk 0.59cvss 9.1epss 0.02
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
- risk 0.59cvss 9.1epss 0.01
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been…
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass intended access restrictions, or to trigger denial of service to traffic…
- risk 0.59cvss 9.0epss 0.01
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
- risk 0.59cvss 9.1epss 0.02
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and…
- risk 0.59cvss 9.1epss 0.01
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
- risk 0.59cvss 9.1epss 0.01
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
- risk 0.59cvss 9.1epss 0.01
A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.
- risk 0.59cvss 9.1epss 0.01
Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.