Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2026-86185HIGHBilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification BypassEPSS 0.2%CVE-2025-36005MEDIUMIBM MQ Operator information disclosureEPSS 0.2%CVE-2025-20126MEDIUMCisco ThousandEyes Endpoint Agent Certificate Validation VulnerabilityEPSS 0.2%CVE-2026-45175HIGHIdira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation ProcessesEPSS 0.2%CVE-2023-6043HIGHA privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and executeEPSS 0.2%CVE-2026-79732LOWDell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. AnEPSS 0.2%CVE-2025-37730MEDIUMLogstash Improper Certificate Validation in TCP outputEPSS 0.2%CVE-2024-30149MEDIUMHCL AppScan Source is affected by an expired TLS/SSL certificateEPSS 0.2%CVE-2025-59347LOWDragonfly Manager makes requests to external endpoints with disabled TLS authenticationEPSS 0.2%CVE-2026-45170HIGHIdira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate ValidationEPSS 0.2%CVE-2023-48785MEDIUMAn improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attaEPSS 0.2%CVE-2026-33248MEDIUMNATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingEPSS 0.2%CVE-2025-64649MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2026-34073LOWcryptography has incomplete DNS name constraint enforcement on peer namesEPSS 0.2%CVE-2026-41714MEDIUMIn Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManagerEPSS 0.2%CVE-2021-21559HIGHDell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in theEPSS 0.2%CVE-2026-66410LOWAndroid and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.EPSS 0.2%CVE-2024-9160MEDIUMSecurity Misconfiguration in Forge module PEADMEPSS 0.2%CVE-2026-4740HIGHRhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validationEPSS 0.2%CVE-2025-23118MEDIUMAn Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent EPSS 0.2%