VYPR

CWE-297

Improper Validation of Certificate with Host Mismatch

VariantIncompleteLikelihood: High

Description

The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (76)

page 4 of 4
  • CVE-2018-19946MedSep 11, 2020
    risk 0.27cvss 4.2epss 0.00

    The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already…

  • CVE-2026-12730LowAug 5, 2026
    risk 0.25cvss 3.8epss 0.00

    IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the…

  • CVE-2025-49015MedJun 18, 2025
    risk 0.25cvss 4.9epss 0.00

    The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

  • CVE-2025-68161MedDec 18, 2025
    risk 0.24cvss 4.8epss 0.01

    The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName …

  • CVE-2022-29082LowMay 26, 2022
    risk 0.24cvss 3.7epss 0.00

    Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 19.5.x,19.5.0.x, 19.6 and 19.6.0.1 and 19.6.0.2 contain an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port 5671 which could…

  • CVE-2020-26234MedDec 8, 2020
    risk 0.24cvss 4.8epss 0.00

    Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of Opencast's HTTP requests. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host.…

  • CVE-2025-46551LowMay 7, 2025
    risk 0.17cvss 3.7epss 0.00

    JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL…

  • CVE-2014-3596Aug 27, 2014
    risk 0.01cvss epss 0.09

    The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a…

  • CVE-2026-58040MedJul 30, 2026
    risk 0.00cvss 6.3epss 0.00

    An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

  • CVE-2026-15243HigJul 24, 2026
    risk 0.00cvss epss 0.00

    Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate…

  • CVE-2026-41603Apr 28, 2026
    risk 0.00cvss epss 0.01

    Rejected reason: This CVE ID is Rejected and will not be used. The record incorrectly described the affected language binding and fixed version. Use CVE-2026-66053, which was assigned to the vulnerability.

  • CVE-2021-21385HigMar 24, 2021
    risk 0.00cvss 8.8epss 0.01

    Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e505f62 disables HTTPS hostname verification of its HTTP client. Additionally it accepted any self-signed certificate as valid.…

  • CVE-2020-15260MedMar 10, 2021
    risk 0.00cvss 6.8epss 0.01

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.10 and earlier, PJSIP transport can be reused if they have the same IP address + port + protocol.…

  • CVE-2020-1887CriMar 13, 2020
    risk 0.00cvss 9.1epss 0.01

    Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.

  • CVE-2014-3604Oct 25, 2014
    risk 0.00cvss epss 0.01

    Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…

  • CVE-2014-3522Aug 19, 2014
    risk 0.00cvss epss 0.06

    The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted…