VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 8 of 80
  • CVE-2020-10925HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2010-4533CriNov 13, 2019
    risk 0.57cvss 9.8epss 0.01

    offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

  • CVE-2019-18632CriOct 30, 2019
    risk 0.57cvss 9.8epss 0.01

    European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.

  • CVE-2019-1010275CriJul 17, 2019
    risk 0.57cvss 9.8epss 0.01

    helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see https://github.com/helm/helm/pull/3152/files/…

  • CVE-2016-1000030CriSep 5, 2018
    risk 0.57cvss 9.8epss 0.02

    Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509…

  • CVE-2018-8059HigMar 11, 2018
    risk 0.57cvss 8.8epss 0.01

    The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directives are used.

  • CVE-2017-7429HigMar 2, 2018
    risk 0.57cvss 8.8epss 0.01

    The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

  • CVE-2015-2320CriJan 8, 2018
    risk 0.57cvss 9.8epss 0.04

    The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

  • CVE-2017-11364HigAug 2, 2017
    risk 0.57cvss 8.8epss 0.02

    The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.

  • CVE-2015-3886CriJul 21, 2017
    risk 0.57cvss 9.8epss 0.02

    libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.

  • CVE-2017-3218HigJun 21, 2017
    risk 0.57cvss 8.8epss 0.00

    Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.

  • CVE-2024-51774HigNov 2, 2024
    risk 0.56cvss 8.1epss 0.03

    qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

  • CVE-2023-43082HigNov 22, 2023
    risk 0.56cvss 8.6epss 0.00

    Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.

  • CVE-2022-4895HigFeb 28, 2023
    risk 0.56cvss 8.6epss 0.00

    Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component) allows Man in the Middle Attack.This issue affects Hitachi Infrastructure Analytics…

  • CVE-2019-1886HigJul 4, 2019
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server…

  • CVE-2018-0277HigMay 17, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to…

  • CVE-2018-6221HigMar 15, 2018
    risk 0.56cvss 8.1epss 0.06

    An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an update file and inject their own.

  • CVE-2026-45175HigJun 11, 2026
    risk 0.55cvss —epss 0.00

    Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could…

  • CVE-2026-1709CriFeb 6, 2026
    risk 0.55cvss 9.4epss 0.06

    A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations,…

  • CVE-2024-29050HigApr 9, 2024
    risk 0.55cvss 8.4epss 0.01

    Windows Cryptographic Services Remote Code Execution Vulnerability