Weaknesses of type CWE-295

869 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-8476HIGHAlpine iLX-507 TIDAL Improper Certificate Validation VulnerabilityEPSS 0.1%CVE-2026-8497HIGHImproper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on AndrEPSS 0.1%CVE-2026-77707MEDIUMTLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render EngineEPSS 0.1%CVE-2026-65118HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%CVE-2024-32865MEDIUMexacqVison - TLS certificate validationEPSS 0.1%CVE-2026-90452MEDIUMRequests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify tEPSS 0.1%CVE-2026-44363MEDIUMUnsafe remote resource fetching in expansion misp-modulesEPSS 0.1%CVE-2025-26478LOWDell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent netwoEPSS 0.1%CVE-2026-2368HIGHAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2026-18678MEDIUMKong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configuredEPSS 0.1%CVE-2026-13327HIGHImproper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positiEPSS 0.1%CVE-2021-22278MEDIUMCertificate verification vulnerability in Update Manager of PCM600 Engineering ToolEPSS 0.1%CVE-2024-35140HIGHIBM Security Verify Access privilege escalationEPSS 0.1%CVE-2026-8480MEDIUMConnection possible to the Administration portal with a revoked certificateEPSS 0.1%CVE-2026-81447MEDIUMDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticaEPSS 0.1%CVE-2026-86474HIGHImproper Certificate Validation in the Firmware Download vulnerabilityEPSS 0.1%CVE-2024-45205HIGHAn Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) couldEPSS 0.1%CVE-2024-47477MEDIUMDell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attackEPSS 0.1%CVE-2026-31798MEDIUMJumpServer Improper Certificate Validation in Custom SMS API ClientEPSS 0.1%CVE-2026-84465HIGHZammad: S/MIME signature verification allows forged sender impersonationEPSS 0.1%