VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,505)

page 74 of 76
  • CVE-2020-29457MedFeb 16, 2021
    risk 0.00cvss 4.4epss 0.00

    A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.

  • CVE-2021-25835HigFeb 8, 2021
    risk 0.00cvss 7.5epss 0.01

    Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with…

  • CVE-2021-3336HigJan 29, 2021
    risk 0.00cvss 8.1epss 0.01

    DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can…

  • CVE-2021-3309HigJan 26, 2021
    risk 0.00cvss 8.1epss 0.02

    packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,

  • CVE-2020-26117HigSep 27, 2020
    risk 0.00cvss 8.1epss 0.03

    In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.

  • CVE-2020-24619MedSep 22, 2020
    risk 0.00cvss 5.9epss 0.01

    In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.

  • CVE-2020-15134HigJul 31, 2020
    risk 0.00cvss 8.0epss 0.01

    Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby version of its client. Those libraries both use the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake…

  • CVE-2020-15133HigJul 31, 2020
    risk 0.00cvss 8.0epss 0.01

    In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever a `wss:` URL is used for the connection.…

  • CVE-2020-15813HigJul 17, 2020
    risk 0.00cvss 8.1epss 0.01

    Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the Graylog client code (in all…

  • CVE-2020-15720MedJul 14, 2020
    risk 0.00cvss 6.8epss 0.01

    In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class,…

  • CVE-2020-13616MedMay 26, 2020
    risk 0.00cvss 5.9epss 0.01

    The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.

  • CVE-2020-10059MedMay 11, 2020
    risk 0.00cvss 4.8epss 0.01

    The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects:…

  • CVE-2020-9321HigMar 16, 2020
    risk 0.00cvss 7.5epss 0.01

    configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.

  • CVE-2020-1887CriMar 13, 2020
    risk 0.00cvss 9.1epss 0.01

    Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.

  • CVE-2020-9434CriFeb 27, 2020
    risk 0.00cvss 9.1epss 0.01

    openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

  • CVE-2020-9433CriFeb 27, 2020
    risk 0.00cvss 9.1epss 0.01

    openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

  • CVE-2020-9432CriFeb 27, 2020
    risk 0.00cvss 9.1epss 0.01

    openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

  • CVE-2020-7956CriJan 31, 2020
    risk 0.00cvss 9.8epss 0.01

    HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.

  • CVE-2018-21029CriOct 30, 2019
    risk 0.00cvss 9.8epss 0.03

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability…

  • CVE-2017-18588MedAug 26, 2019
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.