Weaknesses of type CWE-295

857 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-67229CRITICALAn improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path aEPSS 0.3%CVE-2025-33142MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.3%CVE-2024-42193LOWHCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attackEPSS 0.3%CVE-2024-28021HIGHA vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an aEPSS 0.3%CVE-2026-41016MEDIUMApache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in SMTP providerEPSS 0.3%CVE-2025-65830CRITICALDue to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstEPSS 0.3%CVE-2023-50315MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.3%CVE-2026-9258HIGHImproper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.3%CVE-2026-76242CRITICALstigmem Federation Peer Registration Authentication BypassEPSS 0.3%CVE-2024-47119MEDIUMIBM Storage Defender - Resiliency Service improper certificate validationEPSS 0.3%CVE-2026-67294CRITICALFreeRDP before 3.29.0 TLS Certificate EKU BypassEPSS 0.3%CVE-2023-38686CRITICALSydent does not verify email server certificatesEPSS 0.3%CVE-2025-50944HIGHAn issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X5EPSS 0.3%CVE-2026-1530HIGHFog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validationEPSS 0.3%CVE-2026-90623MEDIUMandreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validationEPSS 0.3%CVE-2026-54919HIGHcpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backendsEPSS 0.3%CVE-2025-29883HIGHFile Station 5EPSS 0.3%CVE-2024-53846MEDIUMssl fails to validate incorrect extened key usageEPSS 0.3%CVE-2025-40801CRITICALA vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional TranslaEPSS 0.3%CVE-2025-33031HIGHFile Station 5EPSS 0.3%