VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 64 of 76
  • CVE-2020-2187MedMay 6, 2020
    risk 0.29cvss 5.6epss 0.00

    Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.

  • CVE-2018-12257MedJun 12, 2018
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the…

  • CVE-2018-1000151MedApr 5, 2018
    risk 0.29cvss 5.6epss 0.00

    A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.

  • CVE-2026-48934MedJun 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-35207MedApr 9, 2026
    risk 0.28cvss 5.4epss 0.00

    dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the…

  • CVE-2025-14819MedJan 8, 2026
    risk 0.28cvss 5.3epss 0.01

    When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations.…

  • CVE-2025-52919MedJun 21, 2025
    risk 0.28cvss 4.3epss 0.00

    In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.

  • CVE-2024-10445MedMar 19, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write…

  • CVE-2024-5918MedNov 14, 2024
    risk 0.28cvss 4.3epss 0.00

    An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is…

  • CVE-2024-23273MedMar 8, 2024
    risk 0.28cvss 4.3epss 0.01

    This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.

  • CVE-2023-33201MedJul 5, 2023
    risk 0.28cvss 5.3epss 0.01

    Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the…

  • CVE-2020-35509MedAug 23, 2022
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

  • CVE-2022-28352MedApr 2, 2022
    risk 0.28cvss 4.3epss 0.00

    WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an arbitrary certificate. NOTE:…

  • CVE-2020-36425MedJul 19, 2021
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

  • CVE-2021-1354MedFeb 4, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager (UCSM). This vulnerability is due to improper certificate…

  • CVE-2020-24025MedJan 11, 2021
    risk 0.28cvss 5.3epss 0.01

    Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

  • CVE-2020-28942MedNov 19, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client certificates (for the RA, not the end user) to a limited…

  • CVE-2020-4340MedSep 23, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180.

  • CVE-2020-16197MedAug 25, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is…

  • CVE-2020-6529MedJul 22, 2020
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.