Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-70043CRITICALAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certEPSS 0.2%CVE-2024-45641MEDIUMIBM Security ReaQta improper certificate validationEPSS 0.2%CVE-2021-26320—Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacEPSS 0.2%CVE-2026-8367MEDIUMaria2c Improper Certificate ValidationEPSS 0.2%CVE-2025-42611MEDIUMImproper certificate validation in multiple RouterOS servicesEPSS 0.2%CVE-2026-54323MEDIUMDaytona: Git credential leak via git clone with TLS verification disabledEPSS 0.2%CVE-2026-50149MEDIUMContour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate EnabledEPSS 0.2%CVE-2025-54470HIGHNeuVector telemetry sender is vulnerable to MITM and DoSEPSS 0.2%CVE-2025-52919MEDIUMIn Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalEPSS 0.2%CVE-2025-68482MEDIUMA improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyEPSS 0.2%CVE-2026-40992MEDIUMMail Auto-Configuration Does Not Enable SSL Hostname VerificationEPSS 0.2%CVE-2024-54147MEDIUMAltair GraphQL Client's desktop app does not validate HTTPS certificatesEPSS 0.2%CVE-2023-6058HIGHHTTPS Certificate Validation Issue in Bitdefender Safepay (VA-11167)EPSS 0.2%CVE-2023-49567HIGHInsecure Trust of certificates using collision hash functions in Bitdefender Total Security HTTPS Scanning (VA-11239)EPSS 0.2%CVE-2026-60648HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.2%CVE-2024-12174LOWAn Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could interceEPSS 0.2%CVE-2025-46551MEDIUMJRuby-OpenSSL has hostname verification disabled by defaultEPSS 0.2%CVE-2025-52598MEDIUMInsufficient certificate validationEPSS 0.2%CVE-2026-66760MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.2%CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.2%