Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2026-74774MEDIUMDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker wiEPSS 0.2%CVE-2026-18717CRITICALImproper Certificate Validation in ASE 2000EPSS 0.2%CVE-2025-12765HIGHpgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.EPSS 0.2%CVE-2025-9291HIGHImproper Certificate Validation in TP-Link Omada Cloud CommunicationsEPSS 0.2%CVE-2025-15612MEDIUMWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEEPSS 0.2%CVE-2023-6056HIGHInsecure Trust of Self-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11164)EPSS 0.2%CVE-2026-90647CRITICALASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in thEPSS 0.2%CVE-2023-47537MEDIUMAn improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 throughEPSS 0.2%CVE-2026-23998HIGHFleet has a Windows MDM management endpoint authentication bypassEPSS 0.2%CVE-2026-24932HIGHAn improper certificate validation vulnerability was found in ADM while updating the DDNS settings.EPSS 0.2%CVE-2026-76362HIGHImproper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAREPSS 0.2%CVE-2023-49570HIGHInsecure Trust of Basic Constraints certificate in Bitdefender Total Security HTTPS Scanning (VA-11210)EPSS 0.2%CVE-2026-41132MEDIUMCKAN: No certificate validation on STMP connectionEPSS 0.2%CVE-2025-2028MEDIUMLack of TLS validationEPSS 0.2%CVE-2025-40744HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate cEPSS 0.2%CVE-2023-6057HIGHInsecure Trust of DSA-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11166)EPSS 0.2%CVE-2026-24933HIGHAn improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.EPSS 0.2%CVE-2025-10495HIGHA potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applicationEPSS 0.2%CVE-2024-41258MEDIUMAn issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing atEPSS 0.2%CVE-2026-22696CRITICALdcap-qvl has Missing Verification for QE IdentityEPSS 0.2%