Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-1001MEDIUMMedixant RadiAnt DICOM Viewer Improper Certificate ValidationEPSS 0.1%CVE-2022-32748HIGHA CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when usingEPSS 0.1%CVE-2026-84850MEDIUMImproper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 aEPSS 0.1%CVE-2026-13385CRITICALAn Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-theEPSS 0.1%CVE-2026-15937MEDIUMAgent receiver certificate confusion allows authentication with a certificate issued for another endpointEPSS 0.1%CVE-2025-30000MEDIUMA vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restriEPSS 0.1%CVE-2026-44305MEDIUMLemur: LDAP TLS certificate verification globally disabled enables credential interceptionEPSS 0.1%CVE-2024-47258HIGH2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates ofEPSS 0.1%CVE-2026-0296MEDIUMGlobalProtect App: Improper Certificate Validation Bypass VulnerabilityEPSS 0.1%CVE-2025-64432MEDIUMKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation LayerEPSS 0.1%CVE-2021-25635MEDIUMContent Manipulation with Certificate Validation AttackEPSS 0.1%CVE-2025-70044MEDIUMAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.EPSS 0.1%CVE-2026-87872MEDIUMCommunity.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosureEPSS 0.1%CVE-2025-40745MEDIUMA vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), SimcenteEPSS 0.1%CVE-2024-4786LOWAn improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device EPSS 0.1%CVE-2025-8476HIGHAlpine iLX-507 TIDAL Improper Certificate Validation VulnerabilityEPSS 0.1%CVE-2026-65129MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%CVE-2025-60022LOWImproper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a maEPSS 0.1%CVE-2026-8497HIGHImproper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on AndrEPSS 0.1%CVE-2026-65118HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%