VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 5 of 80
  • CVE-2023-49312CriNov 26, 2023
    risk 0.59cvss 9.1epss 0.01

    Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.

  • CVE-2022-31733CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are…

  • CVE-2022-42979HigJan 6, 2023
    risk 0.59cvss 8.8epss 0.24

    Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link.

  • CVE-2022-43705CriNov 27, 2022
    risk 0.59cvss 9.1epss 0.00

    In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).

  • CVE-2022-20813CriJul 6, 2022
    risk 0.59cvss 9.0epss 0.01

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected…

  • CVE-2014-8164CriJul 6, 2022
    risk 0.59cvss 9.1epss 0.01

    A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

  • CVE-2021-45490CriMar 28, 2022
    risk 0.59cvss 9.1epss 0.01

    The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.

  • CVE-2021-43882CriDec 15, 2021
    risk 0.59cvss 9.0epss 0.02

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-23155CriNov 18, 2021
    risk 0.59cvss 9.0epss 0.00

    Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior…

  • CVE-2021-33695CriSep 15, 2021
    risk 0.59cvss 9.1epss 0.01

    Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

  • CVE-2020-29663CriDec 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.

  • CVE-2020-9868CriOct 22, 2020
    risk 0.59cvss 9.1epss 0.01

    A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been…

  • CVE-2020-16163CriJul 30, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lack of validation of a TLS HTTPS endpoint. This allows remote attackers to bypass intended access restrictions, or to trigger denial of service to traffic…

  • CVE-2020-11050CriMay 7, 2020
    risk 0.59cvss 9.0epss 0.01

    In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

  • CVE-2020-11580CriApr 6, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.

  • CVE-2019-17560CriMar 30, 2020
    risk 0.59cvss 9.1epss 0.02

    The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and…

  • CVE-2017-17945CriJun 24, 2019
    risk 0.59cvss 9.1epss 0.01

    The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.

  • CVE-2017-17944CriJun 20, 2019
    risk 0.59cvss 9.1epss 0.01

    The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.

  • CVE-2018-5926CriMar 27, 2019
    risk 0.59cvss 9.1epss 0.01

    A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

  • CVE-2019-8351CriMar 21, 2019
    risk 0.59cvss 9.1epss 0.01

    Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.