Weaknesses of type CWE-295

869 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2026-82157HIGHDell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticaEPSS 0.1%CVE-2025-8393HIGHDreame Technology iOS and Android Mobile Applications Improper Certificate ValidationEPSS 0.1%CVE-2024-39771MEDIUMQBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacEPSS 0.1%CVE-2025-65083LOWGoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSigEPSS 0.1%CVE-2025-2183MEDIUMGlobalProtect App: Improper Certificate Validation Leads to Privilege EscalationEPSS 0.1%CVE-2026-40539HIGHAn improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 andEPSS 0.1%CVE-2025-9785HIGHMisconfigured certificate validation with self-signed certificates for Print DeployEPSS 0.1%CVE-2026-54548LOWkas: Persistent SSH Host Key Checking DisablementEPSS 0.1%CVE-2026-16792HIGHGlobal TLS Certificate Validation Bypass in Lenovo XClarity OrchestratorEPSS 0.1%CVE-2024-0042MEDIUMIn TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DEPSS 0.1%CVE-2026-0249MEDIUMGlobalProtect App: Certificate Validation Bypass VulnerabilitiesEPSS 0.1%CVE-2019-25652HIGHUniFi Network Controller Improper Certificate Validation Leading to Credential Theft via MITMEPSS 0.1%CVE-2025-40896MEDIUMLack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0EPSS 0.1%CVE-2025-58126MEDIUMLack of TLS validation in plugin VMware vSAN on Checkmk ExchangeEPSS 0.1%CVE-2026-39984MEDIUMSigstore Timestamp Authority has Improper Certificate Validation in verifierEPSS 0.1%CVE-2025-58125MEDIUMLack of TLS validation in plugin Freebox v6 agent on Checkmk ExchangeEPSS 0.1%CVE-2025-58123MEDIUMLack of TLS validation in plugin BGP Monitoring on Checkmk ExchangeEPSS 0.1%CVE-2025-58127MEDIUMLack of TLS validation in plugin Dell Powerscale on Checkmk ExchangeEPSS 0.1%CVE-2025-58124MEDIUMLack of TLS validation in plugin check-mk-api on Checkmk ExchangeEPSS 0.1%CVE-2025-1002MEDIUMMicroDicom DICOM Viewer Improper Certificate ValidationEPSS 0.1%