Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2024-11621HIGHMissing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modifEPSS 0.2%CVE-2025-11043CRITICALImproper Server Certificate Validation in Automation StudioEPSS 0.2%CVE-2025-59353HIGHManager generates mTLS certificates for arbitrary IP addressesEPSS 0.2%CVE-2022-45856MEDIUMAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 aEPSS 0.2%CVE-2025-56231CRITICALTonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass updaEPSS 0.2%CVE-2024-37311HIGHCollabora Online's remote host TLS certificates are not fully verifiedEPSS 0.2%CVE-2026-63650LOWOpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 usernaEPSS 0.2%CVE-2024-50691HIGHSunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certifEPSS 0.2%CVE-2025-0239MEDIUMAlt-Svc ALPN validation failure when redirectedEPSS 0.2%CVE-2024-23970MEDIUMChargePoint Home Flex Improper Certificate ValidationEPSS 0.2%CVE-2026-47074HIGHex_aws_sns SigningCertURL not validated in verify_message/1EPSS 0.2%CVE-2026-45388CRITICALIn OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersEPSS 0.2%CVE-2026-58162HIGHApache Traffic Server: Certifier plugin trusts client SNI when generating certificatesEPSS 0.2%CVE-2024-27440MEDIUMThe Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly veEPSS 0.2%CVE-2026-23776HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.2%CVE-2026-82180CRITICALIn Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFiEPSS 0.2%CVE-2026-6900CRITICALImproper Certificate ValidationEPSS 0.2%CVE-2025-69412LOWKDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which miEPSS 0.2%CVE-2025-66491MEDIUMTraefik has Inverted TLS Verification Logic in its ingress-nginx ProviderEPSS 0.2%CVE-2026-59836MEDIUMA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiCliEPSS 0.2%