VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 61 of 76
  • CVE-2025-58124MedAug 28, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.

  • CVE-2025-58123MedAug 28, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.

  • CVE-2025-36041MedJun 15, 2025
    risk 0.31cvss 4.7epss 0.00

    IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which…

  • CVE-2025-5025MedMay 28, 2025
    risk 0.31cvss 4.8epss 0.00

    libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that…

  • CVE-2025-22459MedApr 8, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.

  • CVE-2023-48785MedMar 14, 2025
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.

  • CVE-2024-40590MedMar 14, 2025
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated…

  • CVE-2025-20126MedJan 8, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not…

  • CVE-2024-30149MedOct 31, 2024
    risk 0.31cvss 4.8epss 0.00

    HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

  • CVE-2022-45856MedSep 10, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4,…

  • CVE-2024-8285MedAug 30, 2024
    risk 0.31cvss 5.9epss 0.00

    A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the…

  • CVE-2024-33509MedJul 9, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote and unauthenticated attacker in a Man-in-the-Middle position to decipher and/or tamper with the communication…

  • CVE-2023-50179MedJul 9, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and public SDN…

  • CVE-2024-31340MedMay 22, 2024
    risk 0.31cvss 4.8epss 0.00

    TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.

  • CVE-2024-27440MedMar 13, 2024
    risk 0.31cvss 4.8epss 0.00

    The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted…

  • CVE-2023-47537MedFeb 15, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink…

  • CVE-2023-5554MedOct 12, 2023
    risk 0.31cvss 4.8epss 0.00

    Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.

  • CVE-2023-35845MedSep 11, 2023
    risk 0.31cvss 4.7epss 0.00

    Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these files are installed as…

  • CVE-2023-39441MedAug 23, 2023
    risk 0.31cvss 5.9epss 0.01

    Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 certificate. …

  • CVE-2023-29501MedJun 13, 2023
    risk 0.31cvss 4.8epss 0.00

    Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, and Jiyu Kukan Toku-Toku coupon App for Android versions 3.5.0 and earlier are vulnerable to improper server certificate verification. If this vulnerability is exploited, a man-in-the-middle attack may allow an…