VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 79 of 80
  • CVE-2020-13616MedMay 26, 2020
    risk 0.00cvss 5.9epss 0.01

    The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.

  • CVE-2020-10059MedMay 11, 2020
    risk 0.00cvss 4.8epss 0.01

    The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects:…

  • CVE-2020-9321HigMar 16, 2020
    risk 0.00cvss 7.5epss 0.01

    configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.

  • CVE-2020-1887CriMar 13, 2020
    risk 0.00cvss 9.1epss 0.02

    Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.

  • CVE-2020-9434CriFeb 27, 2020
    risk 0.00cvss 9.1epss 0.01

    openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

  • CVE-2020-9433CriFeb 27, 2020
    risk 0.00cvss 9.1epss 0.01

    openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

  • CVE-2020-9432CriFeb 27, 2020
    risk 0.00cvss 9.1epss 0.01

    openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

  • CVE-2020-7956CriJan 31, 2020
    risk 0.00cvss 9.8epss 0.01

    HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.

  • CVE-2018-21029CriOct 30, 2019
    risk 0.00cvss 9.8epss 0.03

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability…

  • CVE-2017-18588MedAug 26, 2019
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.

  • CVE-2019-12855HigJun 16, 2019
    risk 0.00cvss 7.4epss 0.02

    In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

  • CVE-2017-7562MedJul 26, 2018
    risk 0.00cvss 6.5epss 0.03

    An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and…

  • CVE-2018-10406HigJun 13, 2018
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but…

  • CVE-2018-8970HigMar 24, 2018
    risk 0.00cvss 7.4epss 0.01

    The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to…

  • CVE-2015-1796Jul 8, 2015
    risk 0.00cvss —epss 0.01

    The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued…

  • CVE-2015-4094Jun 2, 2015
    risk 0.00cvss —epss 0.01

    The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2015-1852Apr 17, 2015
    risk 0.00cvss —epss 0.03

    The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to…

  • CVE-2014-3394Oct 10, 2014
    risk 0.00cvss —epss 0.01

    The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign…

  • CVE-2014-7144Oct 2, 2014
    risk 0.00cvss —epss 0.02

    OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct…

  • CVE-2014-0363Apr 30, 2014
    risk 0.00cvss —epss 0.01

    The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information…