Weaknesses of type CWE-295

853 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2024-28161MEDIUMIn Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control TowEPSS 0.4%CVE-2021-1354MEDIUMCisco Unified Computing System Central Software Improper Certificate Validation VulnerabilityEPSS 0.4%CVE-2022-1632—An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the defEPSS 0.4%CVE-2025-32878CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is EPSS 0.4%CVE-2021-22511—Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affectsEPSS 0.4%CVE-2024-43201HIGHPlanet Fitness Workouts mobile apps do not properly validate TLS certificatesEPSS 0.4%CVE-2026-42769MEDIUMTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateEPSS 0.4%CVE-2021-1277HIGHCisco Data Center Network Manager Certificate Validation VulnerabilitiesEPSS 0.4%CVE-2021-1276HIGHCisco Data Center Network Manager Certificate Validation VulnerabilitiesEPSS 0.4%CVE-2021-23167HIGHImproper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the CommEPSS 0.4%CVE-2024-8007HIGHOpenstack-tripleo-common: rhosp director disables tls verification for registry mirrorsEPSS 0.4%CVE-2024-42395CRITICALUnauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2025-1014HIGHCertificate length was not properly checkedEPSS 0.4%CVE-2024-45159CRITICALAn issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the clieEPSS 0.4%CVE-2024-7383HIGHLibnbd: nbd server improper certificate validationEPSS 0.4%CVE-2025-1193HIGHImproper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows aEPSS 0.4%CVE-2023-29000MEDIUMNextcloud Desktop client does not verify received singed certificate in end-to-end encryptionEPSS 0.4%CVE-2022-34394LOWDell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unauthenticated attacker EPSS 0.4%CVE-2026-13410HIGHDancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabledEPSS 0.4%CVE-2023-48427HIGHA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificEPSS 0.4%