Weaknesses of type CWE-295

853 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2022-22156MEDIUMJunos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URLEPSS 0.5%CVE-2024-21543MEDIUMVersions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because EPSS 0.5%CVE-2023-47700MEDIUMIBM Storage Virtualize improper certificate validationEPSS 0.5%CVE-2024-25642HIGHImproper Certificate Validation in SAP Cloud ConnectorEPSS 0.5%CVE-2022-24320—A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the cEPSS 0.5%CVE-2025-34199CRITICALVasion Print (formerly PrinterLogic) Insecure SSL Verification Allows Man-in-the-Middle AttacksEPSS 0.5%CVE-2020-15732MEDIUMImproper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attackeEPSS 0.5%CVE-2021-21571MEDIUMDell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validationEPSS 0.5%CVE-2019-3841HIGHKubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into EPSS 0.5%CVE-2023-0509HIGHImproper Certificate Validation in pyload/pyloadEPSS 0.5%CVE-2022-20860HIGHCisco Nexus Dashboard SSL Certificate Validation VulnerabilityEPSS 0.5%CVE-2023-2422MEDIUMKeycloak: oauth client impersonationEPSS 0.5%CVE-2026-20184CRITICALCisco Webex Meetings Certificate Validation VulnerabilityEPSS 0.5%CVE-2024-3738HIGHcym1102 nginxWebUI saveCmd handlePath certificate validationEPSS 0.5%CVE-2026-24734HIGHApache Tomcat Native, Apache Tomcat: OCSP revocation bypassEPSS 0.5%CVE-2022-21657MEDIUMX.509 Extended Key Usage and Trust Purposes bypass in EnvoyEPSS 0.5%CVE-2025-0500HIGHIssue affecting Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV clientsEPSS 0.5%CVE-2023-22367MEDIUMIchiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, whichEPSS 0.5%CVE-2025-46070CRITICALAn issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe componentEPSS 0.5%CVE-2022-46153HIGHRoutes exposed with an empty TLSOption in traefikEPSS 0.5%