VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 60 of 80
  • CVE-2022-1343MedMay 3, 2022
    risk 0.35cvss 5.3epss 0.01

    The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate…

  • CVE-2021-44533MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.09

    Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative…

  • CVE-2021-44532MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.10

    Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name…

  • CVE-2021-32755MedJul 13, 2021
    risk 0.35cvss 5.4epss 0.00

    Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application, a new web socket implementation was introduced for users running iOS 13 or…

  • CVE-2021-22511MedApr 8, 2021
    risk 0.35cvss 6.5epss 0.00

    Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow unconditionally disabling of SSL/TLS certificates.

  • CVE-2021-28363MedMar 15, 2021
    risk 0.35cvss 6.5epss 0.02

    The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This…

  • CVE-2021-20327MedFeb 25, 2021
    risk 0.35cvss 6.4epss 0.00

    A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the…

  • CVE-2021-3285MedJan 26, 2021
    risk 0.35cvss 5.3epss 0.01

    jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.

  • CVE-2020-25680MedJan 7, 2021
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The…

  • CVE-2020-3557MedOct 21, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An…

  • CVE-2020-14039MedJul 17, 2020
    risk 0.35cvss 5.3epss 0.02

    In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

  • CVE-2020-5909MedJul 2, 2020
    risk 0.35cvss 5.4epss 0.00

    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.

  • CVE-2020-2033MedJun 10, 2020
    risk 0.35cvss 5.3epss 0.01

    When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to…

  • CVE-2020-0119MedJun 10, 2020
    risk 0.35cvss 5.3epss 0.01

    In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction…

  • CVE-2020-1113MedMay 21, 2020
    risk 0.35cvss 5.3epss 0.06

    A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An attacker could…

  • CVE-2020-1758MedMay 15, 2020
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

  • CVE-2018-11751MedDec 16, 2019
    risk 0.35cvss 5.4epss 0.01

    Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.

  • CVE-2011-2207MedNov 27, 2019
    risk 0.35cvss 5.3epss 0.01

    dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.

  • CVE-2019-11727MedJul 23, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3…

  • CVE-2019-10334MedJun 11, 2019
    risk 0.35cvss 6.5epss 0.01

    Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.java is used to upload files.