Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-12943MEDIUMImproper certificate validation in firmware update logic in NETGEAR RAX30 and RAXE300EPSS 0.2%CVE-2026-57289MEDIUMJenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for coEPSS 0.2%CVE-2025-12047MEDIUMA vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances,EPSS 0.2%CVE-2026-18257MEDIUMImproper Certificate Validation in S2OPCEPSS 0.2%CVE-2024-48865HIGHQTS, QuTS heroEPSS 0.2%CVE-2026-48437MEDIUMCAI Content Credentials | Improper Certificate Validation (CWE-295)EPSS 0.2%CVE-2025-71063HIGHErrands before 46.2.10 does not verify TLS certificates for CalDAV servers.EPSS 0.2%CVE-2026-79967MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.2%CVE-2023-50179MEDIUMAn improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allowEPSS 0.2%CVE-2026-87733MEDIUMAn issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets acceEPSS 0.2%CVE-2026-66406LOWDEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obEPSS 0.2%CVE-2024-4762HIGHAn improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escEPSS 0.1%CVE-2026-24935MEDIUMAn improper certificate validation vulnerability was found in a third-party NAT traversal module.EPSS 0.1%CVE-2026-15683HIGHLorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation VulnerabilityEPSS 0.1%CVE-2026-27221MEDIUMAcrobat Reader | Improper Certificate Validation (CWE-295)EPSS 0.1%CVE-2026-41859HIGHA network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secrEPSS 0.1%CVE-2026-39388LOWOpenBao's Certificate Authentication Allows Token Renewal With Different CertificateEPSS 0.1%CVE-2025-53869MEDIUMMultiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man-in-the-middle attacEPSS 0.1%CVE-2025-58781MEDIUMWTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.EPSS 0.1%CVE-2025-1001MEDIUMMedixant RadiAnt DICOM Viewer Improper Certificate ValidationEPSS 0.1%