VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 62 of 76
  • CVE-2023-29175MedJun 13, 2023
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to…

  • CVE-2023-31151MedMay 10, 2023
    risk 0.31cvss 4.7epss 0.00

    An Improper Certificate Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote unauthenticated attacker to conduct a man-in-the-middle (MitM) attack. See SEL Service Bulletin dated…

  • CVE-2022-39161MedMay 3, 2023
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks. A man-in-the-middle…

  • CVE-2023-25392MedApr 10, 2023
    risk 0.31cvss 5.9epss 0.00

    Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.

  • CVE-2022-39948MedFeb 16, 2023
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated…

  • CVE-2023-22943MedFeb 14, 2023
    risk 0.31cvss 4.8epss 0.00

    In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs.

  • CVE-2022-32531MedDec 15, 2022
    risk 0.31cvss 5.9epss 0.01

    The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior…

  • CVE-2022-42131MedNov 15, 2022
    risk 0.31cvss 4.8epss 0.00

    Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.

  • CVE-2022-34156MedAug 16, 2022
    risk 0.31cvss 4.8epss 0.00

    'Hulu / フールー' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.

  • CVE-2022-34865MedAug 4, 2022
    risk 0.31cvss 4.8epss 0.00

    In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reached End of…

  • CVE-2022-29222MedMay 21, 2022
    risk 0.31cvss 5.9epss 0.01

    Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for and Pion DTLS wouldn't reject it. This issue affects users that are using Client certificates only.…

  • CVE-2013-10001MedMay 17, 2022
    risk 0.31cvss 4.8epss 0.01

    A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail client. An exploit has been disclosed to the public and may be used.

  • CVE-2022-24968MedFeb 11, 2022
    risk 0.31cvss 5.9epss 0.01

    In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during…

  • CVE-2021-31747MedDec 10, 2021
    risk 0.31cvss 4.8epss 0.00

    Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.

  • CVE-2020-36477MedAug 23, 2021
    risk 0.31cvss 5.9epss 0.01

    An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected…

  • CVE-2021-32069MedAug 13, 2021
    risk 0.31cvss 4.8epss 0.01

    The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation. A successful exploit could allow an attacker to view and modify data.

  • CVE-2021-20649MedFeb 12, 2021
    risk 0.31cvss 4.8epss 0.00

    ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.

  • CVE-2020-5684MedDec 24, 2020
    risk 0.31cvss 4.8epss 0.00

    iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted…

  • CVE-2019-4654MedApr 15, 2020
    risk 0.31cvss 4.8epss 0.00

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-ForceID: 170965.

  • CVE-2019-20455MedFeb 14, 2020
    risk 0.31cvss 5.9epss 0.01

    Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.