VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 57 of 76
  • CVE-2018-11751MedDec 16, 2019
    risk 0.35cvss 5.4epss 0.01

    Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

  • CVE-2011-2207MedNov 27, 2019
    risk 0.35cvss 5.3epss 0.01

    dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.

  • CVE-2019-11727MedJul 23, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3…

  • CVE-2019-10334MedJun 11, 2019
    risk 0.35cvss 6.5epss 0.01

    Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.java is used to upload files.

  • CVE-2019-8337MedFeb 13, 2019
    risk 0.35cvss 5.3epss 0.01

    In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.

  • CVE-2017-7513MedAug 22, 2018
    risk 0.35cvss 5.4epss 0.00

    It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.

  • CVE-2017-2623MedJul 27, 2018
    risk 0.35cvss 5.3epss 0.01

    It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic…

  • CVE-2017-6143MedApr 13, 2018
    risk 0.35cvss 5.4epss 0.00

    X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.

  • CVE-2017-1000417MedJan 22, 2018
    risk 0.35cvss 5.3epss 0.01

    MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

  • CVE-2016-5648MedJun 8, 2017
    risk 0.35cvss 5.3epss 0.01

    Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.

  • CVE-2017-8301MedApr 27, 2017
    risk 0.35cvss 5.3epss 0.01

    LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.

  • CVE-2015-4000LowMay 21, 2015
    risk 0.35cvss 3.7epss 1.00

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by…

  • CVE-2026-39828MedMay 22, 2026
    risk 0.34cvss 6.3epss 0.00

    When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with…

  • CVE-2026-29140MedApr 2, 2026
    risk 0.34cvss 5.3epss 0.00

    SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.

  • CVE-2026-1068MedMar 11, 2026
    risk 0.34cvss 5.3epss 0.00

    An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.

  • CVE-2026-2748MedMar 4, 2026
    risk 0.34cvss 5.3epss 0.00

    SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses containing whitespaces, allowing signature spoofing.

  • CVE-2025-27377MedJan 22, 2026
    risk 0.34cvss 5.3epss 0.00

    Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication…

  • CVE-2025-12047MedNov 12, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the same logical network to disclose sensitive user files from the application.

  • CVE-2025-10699MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.

  • CVE-2025-33142MedAug 14, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.