VYPR

CWE-599

Missing Validation of OpenSSL Certificate

VariantIncomplete

Description

The product uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (15)

  • CVE-2025-12553CriOct 31, 2025
    risk 0.64cvss 9.8epss 0.00

    Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2024-40464HigJul 31, 2024
    risk 0.50cvss 8.8epss 0.01

    An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

  • CVE-2025-56230HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

  • CVE-2024-41265HigAug 1, 2024
    risk 0.49cvss 7.5epss 0.00

    A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.

  • CVE-2022-31105HigJul 12, 2022
    risk 0.47cvss 8.3epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy)…

  • CVE-2026-25060HigFeb 2, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify setting is default to true in the DefaultConfig() function in internal/conf/config.go. This…

  • CVE-2024-41253HigJul 31, 2024
    risk 0.46cvss 7.1epss 0.00

    goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.

  • CVE-2025-56232MedNov 5, 2025
    risk 0.44cvss 6.8epss 0.00

    GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.

  • CVE-2024-36755MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.

  • CVE-2023-48052HigNov 16, 2023
    risk 0.41cvss 7.4epss 0.00

    Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.

  • CVE-2025-56146MedSep 23, 2025
    risk 0.34cvss 5.3epss 0.00

    Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

  • CVE-2026-1778MedFeb 2, 2026
    risk 0.31cvss 5.9epss 0.00

    Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed.

  • CVE-2025-63432MedNov 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a…

  • CVE-2026-62657MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.

  • CVE-2021-21374HigMar 26, 2021
    risk 0.00cvss 8.1epss 0.01

    Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS without full verification of the SSL/TLS certificate due to the default setting of httpClient. An…