Weaknesses of type CWE-295

854 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2026-9058CRITICALImproper Certificate Verification in Szafir SDKEPSS 0.3%CVE-2026-86881CRITICALA certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 aEPSS 0.3%CVE-2026-8286HIGHwrong STARTTLS connection reuseEPSS 0.3%CVE-2025-9708MEDIUMKubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacksEPSS 0.3%CVE-2026-18141HIGHAap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http headerEPSS 0.3%CVE-2025-61778CRITICALAkka.Remote TLS did not properly implement certificate-based authenticationEPSS 0.3%CVE-2024-54848HIGHImproper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a mEPSS 0.3%CVE-2021-27257MEDIUMThis vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEPSS 0.3%CVE-2024-50394HIGHHelpdeskEPSS 0.3%CVE-2024-20385MEDIUMCisco Nexus Dashboard Orchestrator SSL Certificate Validation VulnerabilityEPSS 0.3%CVE-2026-54100HIGHWindows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theftEPSS 0.3%CVE-2023-45613MEDIUMIn JetBrains Ktor before 2.3.5 server certificates were not verifiedEPSS 0.3%CVE-2026-55001HIGHActive Directory Domain Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-5279HIGHIssue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider pluginEPSS 0.3%CVE-2025-34066HIGHAVTECH IP camera, DVR, and NVR Devices Unauthenticated Information DisclosureEPSS 0.3%CVE-2026-22747MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.3%CVE-2026-30836CRITICALStep CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)EPSS 0.3%CVE-2024-5445LOWEcosystem Agent Insufficient Transport Layer SecurityEPSS 0.3%CVE-2023-43082HIGH Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by EPSS 0.3%CVE-2022-3913MEDIUMRapid7 Nexpose Certificate Validation IssueEPSS 0.3%